CVE-2022-39370
Published on: Not Yet Published
Last Modified on: 11/03/2022 06:39:00 PM UTC
Certain versions of Glpi from Glpi-project contain the following vulnerability:
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This issue has been patched, please upgrade to 10.0.4. As a workaround, delete the `install/update.php` script.
- CVE-2022-39370 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
glpi-project - glpi version >= 0.70, < 10.0.4
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Improper access to debug panel · Advisory · glpi-project/glpi · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Glpi-project | Glpi | All | All | All | All |
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-39370 : GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management So… twitter.com/i/web/status/1… | 2022-11-03 15:24:37 |
![]() |
Glpi - CVE-2022-39370: github.com/glpi-project/g… | 2022-11-03 19:01:43 |
![]() |
CVE-2022-39370 | 2022-11-03 16:39:14 |