CVE-2020-11035
Summary
| CVE | CVE-2020-11035 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-05 22:15:00 UTC |
| Updated | 2023-11-07 03:14:00 UTC |
| Description | In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: glpi-9.4.6-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: glpi-9.4.6-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| weak csrf tokens · Advisory · glpi-project/glpi · GitHub |
CONFIRM |
github.com |
Technical Description |
| [SECURITY] Fedora 32 Update: glpi-9.4.6-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: glpi-9.4.6-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690594 Free Berkeley Software Distribution (FreeBSD) Security Update for glpi (b64edef7-3b10-11eb-af2a-080027dbe4b7)