CVE-2025-27147: GLPI Inventory plugin has Improper Access Control Vulnerability
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPI Inventory Pluginto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27147?
CVE-2025-27147 is classified as a high severity vulnerability due to improper access control in the GLPI Inventory Plugin.
How do I fix CVE-2025-27147?
To fix CVE-2025-27147, upgrade the GLPI Inventory Plugin to version 1.5.0 or later.
What versions are affected by CVE-2025-27147?
CVE-2025-27147 affects all versions of the GLPI Inventory Plugin prior to version 1.5.0.
What type of tasks does the GLPI Inventory Plugin handle that is impacted by CVE-2025-27147?
CVE-2025-27147 impacts tasks such as network discovery, software deployment, and data collection within the GLPI Inventory Plugin.
Is the GLPI Inventory Plugin still secure after the patch for CVE-2025-27147?
Yes, the GLPI Inventory Plugin is secure after upgrading to version 1.5.0, which addresses the access control issues.