{"api_version":"1","generated_at":"2026-07-23T22:00:50+00:00","cve":"CVE-2021-43779","urls":{"html":"https://cve.report/CVE-2021-43779","api":"https://cve.report/api/cve/CVE-2021-43779.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43779","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43779"},"summary":{"title":"CVE-2021-43779","description":"GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-01-05 19:15:00","updated_at":"2022-08-09 00:52:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://github.com/pluginsGLPI/addressing/commit/6f55964803054a5acb5feda92c7c7f1d91ab5366","name":"https://github.com/pluginsGLPI/addressing/commit/6f55964803054a5acb5feda92c7c7f1d91ab5366","refsource":"MISC","tags":[],"title":"fix Remote Command Execution vulnerability · pluginsGLPI/addressing@6f55964 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/pluginsGLPI/addressing/security/advisories/GHSA-q5fp-xpr8-77jh","name":"https://github.com/pluginsGLPI/addressing/security/advisories/GHSA-q5fp-xpr8-77jh","refsource":"CONFIRM","tags":[],"title":"Remote Command Execution vulnerability · Advisory · pluginsGLPI/addressing · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/hansmach1ne/MyExploits/tree/main/RCE_GLPI_addressing_plugin","name":"https://github.com/hansmach1ne/MyExploits/tree/main/RCE_GLPI_addressing_plugin","refsource":"MISC","tags":[],"title":"MyExploits/RCE_GLPI_addressing_plugin at main · hansmach1ne/MyExploits · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43779","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43779","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43779","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teclib-edition","cpe5":"addressing","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"glpi","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-43779","STATE":"PUBLIC","TITLE":"Remote Command Execution vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"addressing","version":{"version_data":[{"version_value":"< 2.9.1"}]}}]},"vendor_name":"pluginsGLPI"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20: Improper Input Validation"}]}]},"references":{"reference_data":[{"name":"https://github.com/pluginsGLPI/addressing/security/advisories/GHSA-q5fp-xpr8-77jh","refsource":"CONFIRM","url":"https://github.com/pluginsGLPI/addressing/security/advisories/GHSA-q5fp-xpr8-77jh"},{"name":"https://github.com/pluginsGLPI/addressing/commit/6f55964803054a5acb5feda92c7c7f1d91ab5366","refsource":"MISC","url":"https://github.com/pluginsGLPI/addressing/commit/6f55964803054a5acb5feda92c7c7f1d91ab5366"},{"refsource":"MISC","name":"https://github.com/hansmach1ne/MyExploits/tree/main/RCE_GLPI_addressing_plugin","url":"https://github.com/hansmach1ne/MyExploits/tree/main/RCE_GLPI_addressing_plugin"}]},"source":{"advisory":"GHSA-q5fp-xpr8-77jh","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-01-05 19:15:00","lastModifiedDate":"2022-08-09 00:52:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.1,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:teclib-edition:addressing:*:*:*:*:*:glpi:*:*","versionEndExcluding":"2.9.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43779","Ordinal":"221325","Title":"CVE-2021-43779","CVE":"CVE-2021-43779","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43779","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}