PT-2021-22464 · Glpi+1 · Glpi+1
Trasher
·
Published
2021-09-15
·
Updated
2024-05-22
·
CVE-2021-39211
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions 9.2 through 9.5.5
Description
The issue concerns the disclosure of GLPI and server information through the telemetry endpoint. This problem is fixed in version 9.5.6.
Recommendations
For versions 9.2 through 9.5.5, as a temporary workaround, consider removing the file
ajax/telemetry.php to prevent information disclosure, as it is not needed for the usual functions of GLPI.
Update to version 9.5.6 to fully resolve the issue.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Glpi