CVE-2021-43779
Summary
| CVE | CVE-2021-43779 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-05 19:15:00 UTC |
| Updated | 2022-08-09 00:52:00 UTC |
| Description | GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Teclib-edition | Addressing | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix Remote Command Execution vulnerability · pluginsGLPI/addressing@6f55964 · GitHub | MISC | github.com | |
| Remote Command Execution vulnerability · Advisory · pluginsGLPI/addressing · GitHub | CONFIRM | github.com | |
| MyExploits/RCE_GLPI_addressing_plugin at main · hansmach1ne/MyExploits · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.