CVE-2021-39213
Summary
| CVE | CVE-2021-39213 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-15 17:15:00 UTC |
| Updated | 2021-09-28 16:55:00 UTC |
| Description | GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Glpi-project | Glpi | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 9.5.6 · glpi-project/glpi · GitHub | MISC | github.com | |
| IP restriction on GLPI API Bypass with custom header injection · Advisory · glpi-project/glpi · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.