CVE-2022-24867 Information
Jun 07, 2022
cve
Description
GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features licenses tracking and software auditing. When you pass the config to the javascript some entries are filtered out. The variable ldap_pass is not filtered and when you look at the source code of the rendered page we can see the password for the root dn. Users are advised to upgrade. There is no known workaround for this issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/glpi-project/glpi/commit/26f0a20810db11641afdcf671bac7a309acbb94e https://github.com/glpi-project/glpi/security/advisories/GHSA-4r49-52q9-5fgr
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: