CVE-2024-50339: GLPI vulnerable to unauthenticated session hijacking
Published Dec 11, 2024
·Updated
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=9.5.0<10.0.17
Event History
Dec 11, 2024
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionWeakness
Dec 12, 2024
Data Sourced
via NVD·02:06 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-50339?
CVE-2024-50339 is considered a critical vulnerability due to the potential for session hijacking by unauthenticated users.
2
How do I fix CVE-2024-50339?
To fix CVE-2024-50339, upgrade to GLPI version 10.0.17 or later, where the vulnerability has been patched.
3
Who is affected by CVE-2024-50339?
CVE-2024-50339 affects all users of GLPI versions 9.5.0 to 10.0.16.
4
What does CVE-2024-50339 allow an attacker to do?
CVE-2024-50339 allows an attacker to retrieve session IDs and potentially hijack valid user sessions.
5
Is CVE-2024-50339 a remote vulnerability?
Yes, CVE-2024-50339 can be exploited remotely by unauthenticated users.