Package glpi: Information

  • Default inline alert: Version in the repository: 9.5.13-alt1

Source package: glpi
Version: 9.5.9-alt1
Build time:  Sep 23, 2022, 06:16 PM in the task #307140
Category: Networking/Other
Report package bug
License: GPLv2
Summary: IT and asset management software
Description: 
GLPI is the Information Resource-Manager with an additional Administration-
Interface.
You can use it to build up a database with an inventory for your company
(computer, software, printers...).
It has enhanced functions to make the daily life for the administrators easier,
like a job-tracking-system with mail-notification and methods to build a
database with basic information about your network-topology.

List of rpms provided by this srpm:
glpi (noarch)
glpi-apache2 (noarch)
glpi-php7 (noarch)

Maintainer: Pavel Zilke

List of contributors:
Pavel Zilke

    1. rpm-macros-webserver-common

Last changed


Sept. 14, 2022 Pavel Zilke 9.5.9-alt1
- New version 9.5.9
- This release fixes several critical security issues that has been recently discovered. Update is strongly recommended!
- Security fixes:
 + CVE-2022-35945 : XSS through registration API
 + CVE-2022-31143 : Leak of sensitive information through login page error
 + CVE-2022-35914 : [critical] Command injection using a third-party library script
 + CVE-2022-35946 : SQL injection through plugin controller
 + CVE-2022-35947 : [critical] Authentication via SQL injection
 + CVE-2022-36112 : Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
July 4, 2022 Pavel Zilke 9.5.8-alt1
- New version 9.5.8
- This is a security release, upgrading is recommended
- Security fixes:
 + CVE-2022-31061 : SQL injection on login page
 + CVE-2022-24868 : XSS / open redirect via SVG file upload
 + CVE-2022-24869 : Cross Site CSS Injection
Jan. 27, 2022 Pavel Zilke 9.5.7-alt1
- New version 9.5.7
- This is a security release, upgrading is recommended
- Security fixes:
 + CVE-2022-21720 : SQL injection using custom CSS administration form
 + CVE-2022-21719 : Reflected XSS using reload button