PT-2021-14424 · Glpi+1 · Glpi+1

Trasher

+1

·

Published

2021-03-08

·

Updated

2024-05-22

·

CVE-2021-21327

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.5.4
Description The issue allows a non-authenticated user to remotely instantiate objects of any class in the GLPI environment, potentially leading to malicious attacks or the start of a "POP chain". This affects the integrity of the GLPI core platform and third-party plugins runtime, particularly those with sensitive operations in their constructors or destructors.
Recommendations For versions prior to 9.5.4, update to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive classes and their constructors or destructors to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1583
ALT-PU-2021-1660
ALT-PU-2024-8094
CVE-2021-21327
GHSA-QMW7-W2M4-RJWP

Affected Products

Alt Linux
Glpi