PT-2020-12501 · Teclib+1 · Glpi+1

Trasher

·

Published

2020-05-05

·

Updated

2021-09-14

·

CVE-2020-11033

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.1 through 9.4.6
Description The issue allows any API user with READ right on User itemtype to access the full list of users when querying "apirest.php/User". The response contains all api tokens which can be used for privileges escalations or to read/update/delete data normally non accessible to the current user, and all personal tokens can display another user's planning. Exploiting this requires the API to be enabled and a technician account.
Recommendations For versions 9.1 through 9.4.6, update to version 9.4.6 to resolve the issue. As a temporary workaround, consider adding an application token to mitigate the vulnerability.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2358
ALT-PU-2020-2455
CVE-2020-11033
GHSA-RF54-3R4W-4H55
MGASA-2020-0220

Affected Products

Alt Linux
Glpi