CVE-2024-38370: GLPI allows API document download without rights
Published Nov 15, 2024
·Updated
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
Affected Software
2 affected components
GLPI GLPI>9.2.0<=11.0.0
GLPI-PROJECT GLPI>=9.2.0<10.0.16
Event History
Nov 15, 2024
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 15, 57083
Event
via NVD·09:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-38370?
CVE-2024-38370 has been classified with a high severity due to unauthorized document access via the API.
2
How do I fix CVE-2024-38370?
To resolve CVE-2024-38370, upgrade GLPI to version 10.0.16 or later.
3
Which versions of GLPI are affected by CVE-2024-38370?
CVE-2024-38370 affects GLPI versions from 9.2.0 up to but not including 11.0.0.
4
What type of vulnerability is CVE-2024-38370?
CVE-2024-38370 is identified as an access control vulnerability allowing document downloads without appropriate rights.
5
Who is responsible for addressing CVE-2024-38370?
It is the responsibility of GLPI users to monitor their installations and implement updates to mitigate CVE-2024-38370.