CVE-2022-24867
LDAP password exposure in glpi
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the source code of the rendered page, we can see the password for the root dn. Users are advised to upgrade. There is no known workaround for this issue.
GLPI es un paquete gratuito de software de administración de activos y TI, que proporciona funciones de Service Desk de ITIL, seguimiento de licencias y auditoría de software. Cuando es pasada la configuración al javascript, son filtradas algunas entradas. La variable ldap_pass no es filtrada y cuando es visualizado el código fuente de la página renderizada, podemos visualizar la contraseña del dn root. Es recomendado a usuarios actualizar. No se presenta ninguna mitigación conocida para este problema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-21 CVE Published
- 2023-11-12 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/glpi-project/glpi/security/advisories/GHSA-4r49-52q9-5fgr | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/glpi-project/glpi/commit/26f0a20810db11641afdcf671bac7a309acbb94e | 2022-05-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Glpi-project Search vendor "Glpi-project" | Glpi Search vendor "Glpi-project" for product "Glpi" | < 10.0.0 Search vendor "Glpi-project" for product "Glpi" and version " < 10.0.0" | - |
Affected
|