First published: Fri Nov 15 2024(Updated: )
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >9.2.0<=11.0.0 | |
Teclib GLPI | >=9.2.0<10.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38370 has been classified with a high severity due to unauthorized document access via the API.
To resolve CVE-2024-38370, upgrade GLPI to version 10.0.16 or later.
CVE-2024-38370 affects GLPI versions from 9.2.0 up to but not including 11.0.0.
CVE-2024-38370 is identified as an access control vulnerability allowing document downloads without appropriate rights.
It is the responsibility of GLPI users to monitor their installations and implement updates to mitigate CVE-2024-38370.