Vulnerability CVE-2024-23645: Information
Description
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
Severity: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glpi | sisyphus | 10.0.12-alt1 | 10.0.18-alt1 | ALT-PU-2024-2541-1 | 340947 | Fixed |
glpi | sisyphus_e2k | 10.0.12-alt1 | 10.0.18-alt1 | ALT-PU-2024-2654-1 | - | Fixed |
glpi | sisyphus_loongarch64 | 10.0.12-alt1 | 10.0.18-alt1 | ALT-PU-2024-2569-1 | - | Fixed |
glpi | p10 | 10.0.12-alt1 | 10.0.16-alt1 | ALT-PU-2024-2543-2 | 340950 | Fixed |
glpi | p10_e2k | 10.0.12-alt1 | 10.0.16-alt1 | ALT-PU-2024-2788-1 | - | Fixed |
glpi | c10f2 | 10.0.15-alt1 | 10.0.17-alt1 | ALT-PU-2024-7857-3 | 348178 | Fixed |
glpi | p11 | 10.0.12-alt1 | 10.0.18-alt1 | ALT-PU-2024-2541-1 | 340947 | Fixed |