Vulnerability CVE-2024-23645: Information
Description
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
Severity: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| glpi | sisyphus | 10.0.12-alt1 | 11.0.5-alt1 | ALT-PU-2024-2541-1 | 340947 | Fixed |
| glpi | sisyphus_e2k | 10.0.12-alt1 | 10.0.24-alt1 | ALT-PU-2024-2654-1 | - | Fixed |
| glpi | sisyphus_loongarch64 | 10.0.12-alt1 | 11.0.5-alt1 | ALT-PU-2024-2569-1 | - | Fixed |
| glpi | p11 | 10.0.12-alt1 | 10.0.24-alt1 | ALT-PU-2024-2541-1 | 340947 | Fixed |
| glpi | p10 | 10.0.12-alt1 | 10.0.23-alt0.p10.1 | ALT-PU-2024-2543-2 | 340950 | Fixed |
| glpi | p10_e2k | 10.0.12-alt1 | 10.0.23-alt0.p10.1 | ALT-PU-2024-2788-1 | - | Fixed |
| glpi | c10f2 | 10.0.15-alt1 | 10.0.23-alt0.p10.1 | ALT-PU-2024-7857-3 | 348178 | Fixed |
| glpi | c9f2 | 9.5.13-alt2.c9.1 | 9.5.13-alt1 | ALT-PU-2025-7685-1 | 386097 | Testing |