PT-2022-7400 · Glpi+2 · Glpi+2

Trasher

+1

·

Published

2022-09-15

·

Updated

2024-07-26

·

CVE-2022-39276

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.4
Description The issue is related to the usage of RSS feeds or an external calendar in planning, which is subject to a Server-Side Request Forgery (SSRF) exploit. If a remote script returns a redirect response, the redirect target URL is not checked against the URL allow list defined by the administrator. This could allow a remote attacker to redirect users to an arbitrary URL.
Recommendations For versions prior to 10.0.4, upgrade to version 10.0.4 to resolve the issue. As a temporary workaround, consider disabling the usage of RSS feeds or external calendars in planning until the patch is applied. Restrict access to the planning feature to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2022-3008
ALT-PU-2022-3078
ALT-PU-2022-3274
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
BDU:2024-05812
CVE-2022-39276
GHSA-8VWG-7X42-7V6P

Affected Products

Alt Linux
Glpi
Red Os