PT-2023-24778 · Unknown+1 · Glpi Agent+1

Alemmi

+1

·

Published

2023-06-23

·

Updated

2024-08-12

·

CVE-2023-34254

CVSS v3.1

7.6

High

VectorAV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI Agent versions prior to 1.5
Description The issue affects the GLPI Agent, a generic management agent, when running the remoteinventory task against a Unix platform using the ssh command. An administrator user on the remote system can inject a command into a specific workflow that the agent runs with its privileges. If the agent is running with administration privileges, a malicious user could gain high privileges on the computer running the GLPI Agent. Additionally, a malicious user could disclose all remote accesses configured for the remoteinventory task.
Recommendations For versions prior to 1.5, update to version 1.5 to resolve the issue. As a temporary workaround, consider restricting the privileges of the GLPI Agent when running the remoteinventory task to minimize the risk of exploitation. Restrict access to the remoteinventory task to trusted users only.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-34254
GHSA-39VC-HXGM-J465

Affected Products

Glpi Agent
Red Os