Vulnerability CVE-2024-27098: Information

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.

Published: March 18, 2024
Modified: March 18, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.14-alt110.0.15-alt1ALT-PU-2024-4487-1343562Fixed
glpisisyphus_e2k10.0.14-alt110.0.15-alt1ALT-PU-2024-4589-1-Fixed
glpisisyphus_loongarch6410.0.14-alt110.0.15-alt1ALT-PU-2024-4596-1-Fixed
glpip1010.0.14-alt110.0.15-alt1ALT-PU-2024-4750-2343937Fixed
glpip10_e2k10.0.14-alt110.0.15-alt1ALT-PU-2024-4884-1-Fixed
glpic10f110.0.15-alt110.0.15-alt1ALT-PU-2024-8030-2348513Fixed

References to Advisories, Solutions, and Tools