{"api_version":"1","generated_at":"2026-07-24T02:25:00+00:00","cve":"CVE-2021-21255","urls":{"html":"https://cve.report/CVE-2021-21255","api":"https://cve.report/api/cve/CVE-2021-21255.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21255","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21255"},"summary":{"title":"CVE-2021-21255","description":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-03-02 20:15:00","updated_at":"2022-10-14 13:01:00"},"problem_types":["CWE-639"],"metrics":[],"references":[{"url":"https://github.com/glpi-project/glpi/commit/aade65b7f67d46f23d276a8acb0df70651c3b1dc","name":"https://github.com/glpi-project/glpi/commit/aade65b7f67d46f23d276a8acb0df70651c3b1dc","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"validate entity_restrict when available with idor tokens · glpi-project/glpi@aade65b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-v3m5-r3mx-ff9j","name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-v3m5-r3mx-ff9j","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"entities switch IDOR · Advisory · glpi-project/glpi · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21255","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21255","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glpi-project","cpe5":"glpi","cpe6":"9.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"21255","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glpi-project","cpe5":"glpi","cpe6":"9.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-21255","STATE":"PUBLIC","TITLE":"entities switch IDOR"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"glpi","version":{"version_data":[{"version_value":"= 9.5.3"}]}}]},"vendor_name":"glpi-project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-862 Missing Authorization"}]}]},"references":{"reference_data":[{"name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-v3m5-r3mx-ff9j","refsource":"CONFIRM","url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-v3m5-r3mx-ff9j"},{"name":"https://github.com/glpi-project/glpi/commit/aade65b7f67d46f23d276a8acb0df70651c3b1dc","refsource":"MISC","url":"https://github.com/glpi-project/glpi/commit/aade65b7f67d46f23d276a8acb0df70651c3b1dc"}]},"source":{"advisory":"GHSA-v3m5-r3mx-ff9j","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-03-02 20:15:00","lastModifiedDate":"2022-10-14 13:01:00","problem_types":["CWE-639"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.7,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.1,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:glpi-project:glpi:9.5.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21255","Ordinal":"195381","Title":"CVE-2021-21255","CVE":"CVE-2021-21255","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21255","Ordinal":"1","NoteData":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21255","Ordinal":"2","NoteData":"2021-03-02","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21255","Ordinal":"3","NoteData":"2021-03-02","Type":"Other","Title":"Modified"}]}}}