PT-2021-22464 · Glpi+1 · Glpi+1

Trasher

·

Published

2021-09-15

·

Updated

2024-05-22

·

CVE-2021-39211

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.2 through 9.5.5
Description The issue concerns the disclosure of GLPI and server information through the telemetry endpoint. This problem is fixed in version 9.5.6.
Recommendations For versions 9.2 through 9.5.5, as a temporary workaround, consider removing the file ajax/telemetry.php to prevent information disclosure, as it is not needed for the usual functions of GLPI. Update to version 9.5.6 to fully resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3030
ALT-PU-2021-3038
ALT-PU-2021-3059
ALT-PU-2024-8094
CVE-2021-39211
GHSA-XX66-V3G5-W825

Affected Products

Alt Linux
Glpi