CVE-2024-53850: The Addressing GLPI plugin allows data enumeration through uncontrolled object instantiation
Published Dec 26, 2024
·Updated
The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with 3.0.0 and before 3.0.3, a poor security check allows an unauthenticated attacker to determine whether data exists (by name) in GLPI.
Affected Software
1 affected component
GLPI Addressing GLPI plugin>=3.0.0<3.0.3
Event History
Dec 26, 2024
CVE Published
via MITRE·09:41 PM
Data Sourced
via MITRE·09:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-53850?
CVE-2024-53850 has a medium severity level due to the potential for data exposure.
2
How do I fix CVE-2024-53850?
To fix CVE-2024-53850, upgrade the Addressing GLPI plugin to version 3.0.3 or later.
3
Who is affected by CVE-2024-53850?
Users of the GLPI Addressing plugin versions 3.0.0 to 3.0.3 are affected by CVE-2024-53850.
4
What type of attack does CVE-2024-53850 enable?
CVE-2024-53850 allows unauthenticated attackers to enumerate existing data by name.
5
What can an attacker do with CVE-2024-53850?
An attacker can discover whether specific data exists in the GLPI system without authentication using CVE-2024-53850.