PT-2022-11910 · Glpi · Glpi

Hansmach1Ne

·

Published

2022-01-05

·

Updated

2022-08-09

·

CVE-2021-43779

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 2.9.1
Description GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin suffers from authenticated Remote Code Execution, allowing access to the server's underlying operating system using command injection abuse of functionality.
Recommendations For versions prior to 2.9.1, upgrade to version 2.9.1 or later. As a temporary workaround, consider disabling the addressing plugin until a patch is available.

Exploit

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-43779
GHSA-Q5FP-XPR8-77JH

Affected Products

Glpi