CVE-2022-31068
Sensitive Data Exposure on Refused Inventory Files in GLPI
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is not authenticated. This issue has been addressed in version 10.0.2 and all affected users are advised to upgrade.
GLPI es un paquete de software gratuito de administración de activos y TI, administración de centros de datos, ITIL Service Desk, seguimiento de licencias y auditoría de software. En las versiones afectadas todas las instancias de GLPI con el inventario nativo usado pueden filtrar información confidencial. La funcionalidad para conseguir el archivo rechazado no está autenticada. Este problema ha sido abordado en la versión 10.0.2 y es recomendado a todos los usuarios afectados actualizar
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-28 CVE Published
- 2024-02-03 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/glpi-project/glpi/security/advisories/GHSA-g4hm-6vfr-q3wg | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/glpi-project/glpi/commit/9953a644777e4167b06db9e14fc93b945a557be5 | 2022-07-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Glpi-project Search vendor "Glpi-project" | Glpi Search vendor "Glpi-project" for product "Glpi" | >= 10.0.0 < 10.0.2 Search vendor "Glpi-project" for product "Glpi" and version " >= 10.0.0 < 10.0.2" | - |
Affected
|