Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45179 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Glpi-project
Glpi-project glpi |
|
| Metrics |
cvssV3_1
|
Wed, 11 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Dec 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue. | |
| Title | GLPI vulnerable to unauthenticated session hijacking | |
| Weaknesses | CWE-287 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-11T18:31:59.719Z
Reserved: 2024-10-22T17:54:40.954Z
Link: CVE-2024-50339
Updated: 2024-12-11T18:31:38.303Z
Status : Analyzed
Published: 2024-12-12T02:06:19.147
Modified: 2025-01-10T18:48:11.093
Link: CVE-2024-50339
No data.
OpenCVE Enrichment
No data.
EUVD