{"api_version":"1","generated_at":"2026-07-23T12:08:22+00:00","cve":"CVE-2020-11035","urls":{"html":"https://cve.report/CVE-2020-11035","api":"https://cve.report/api/cve/CVE-2020-11035.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-11035","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-11035"},"summary":{"title":"CVE-2020-11035","description":"In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-05-05 22:15:00","updated_at":"2023-11-07 03:14:00"},"problem_types":["CWE-327"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/","name":"FEDORA-2020-885e2343ed","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 31 Update: glpi-9.4.6-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/","name":"FEDORA-2020-885e2343ed","refsource":"","tags":[],"title":"[SECURITY] Fedora 31 Update: glpi-9.4.6-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-w7q8-58qp-vmpf","name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-w7q8-58qp-vmpf","refsource":"CONFIRM","tags":["Technical Description"],"title":"weak csrf tokens · Advisory · glpi-project/glpi · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/","name":"FEDORA-2020-ee30e1109f","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 32 Update: glpi-9.4.6-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/","name":"FEDORA-2020-ee30e1109f","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: glpi-9.4.6-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11035","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11035","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"11035","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11035","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11035","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glpi-project","cpe5":"glpi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11035","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glpi-project","cpe5":"glpi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-11035","qid":"690594","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for glpi (b64edef7-3b10-11eb-af2a-080027dbe4b7)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-11035","STATE":"PUBLIC","TITLE":"weak CSRF tokens in GLPI"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GLPI","version":{"version_data":[{"version_value":"> 0.83.3, < 9.4.6"}]}}]},"vendor_name":"glpi-project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm"}]}]},"references":{"reference_data":[{"name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-w7q8-58qp-vmpf","refsource":"CONFIRM","url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-w7q8-58qp-vmpf"},{"refsource":"FEDORA","name":"FEDORA-2020-ee30e1109f","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/"},{"refsource":"FEDORA","name":"FEDORA-2020-885e2343ed","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/"}]},"source":{"advisory":"GHSA-w7q8-58qp-vmpf","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-05-05 22:15:00","lastModifiedDate":"2023-11-07 03:14:00","problem_types":["CWE-327"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":4.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","versionStartIncluding":"0.83.3","versionEndExcluding":"9.4.6","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"11035","Ordinal":"171580","Title":"CVE-2020-11035","CVE":"CVE-2020-11035","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"11035","Ordinal":"1","NoteData":"In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"11035","Ordinal":"2","NoteData":"2020-05-05","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"11035","Ordinal":"3","NoteData":"2020-05-15","Type":"Other","Title":"Modified"}]}}}