GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Glpi-project
Glpi-project glpi |
|
CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
Vendors & Products |
Glpi-project
Glpi-project glpi |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16. | |
Title | GLPI allows API document download without rights | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T21:12:56.606Z
Updated: 2024-11-18T19:02:59.188Z
Reserved: 2024-06-14T14:16:16.466Z
Link: CVE-2024-38370
Vulnrichment
Updated: 2024-11-18T19:02:44.085Z
NVD
Status : Awaiting Analysis
Published: 2024-11-15T22:15:15.317
Modified: 2024-11-18T17:11:56.587
Link: CVE-2024-38370
Redhat
No data.