PT-2022-10890 · Glpi · Sccm Plugin For Glpi

Cedric-Anne

·

Published

2022-09-22

·

Updated

2023-07-17

·

CVE-2021-39190

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SCCM plugin for GLPI versions prior to 2.3.0
Description The SCCM plugin for GLPI has an issue where the Configuration page is publicly accessible in read-only mode in versions prior to 2.3.0. This issue is patched in version 2.3.0.
Recommendations For versions prior to 2.3.0, update to version 2.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the Configuration page until the update is applied.

Fix

Information Disclosure

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-39190
GHSA-3324-57W6-JXCQ

Affected Products

Sccm Plugin For Glpi