PT-2023-24778 · Unknown+1 · Glpi Agent+1
Alemmi
+1
·
Published
2023-06-23
·
Updated
2024-08-12
·
CVE-2023-34254
CVSS v3.1
7.6
High
| Vector | AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GLPI Agent versions prior to 1.5
Description
The issue affects the GLPI Agent, a generic management agent, when running the remoteinventory task against a Unix platform using the ssh command. An administrator user on the remote system can inject a command into a specific workflow that the agent runs with its privileges. If the agent is running with administration privileges, a malicious user could gain high privileges on the computer running the GLPI Agent. Additionally, a malicious user could disclose all remote accesses configured for the remoteinventory task.
Recommendations
For versions prior to 1.5, update to version 1.5 to resolve the issue. As a temporary workaround, consider restricting the privileges of the GLPI Agent when running the remoteinventory task to minimize the risk of exploitation. Restrict access to the remoteinventory task to trusted users only.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi Agent
Red Os