PT-2024-5861 · Glpi+2 · Glpi+2

0Xmupa

·

Published

2024-07-10

·

Updated

2025-01-07

·

CVE-2024-37147

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.16
Description The issue is related to incorrect access control in the GLPI system, which provides ITIL Service Desk features, licenses tracking, and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. This can allow a remote attacker to bypass current access restriction rules.
Recommendations For versions prior to 10.0.16, upgrade to version 10.0.16 to resolve the issue. As a temporary workaround, consider restricting access to document attachment features to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10022
ALT-PU-2024-9613
BDU:2024-06608
CVE-2024-37147
GHSA-F2CG-FC85-FFMH

Affected Products

Alt Linux
Glpi
Red Os