Vulnerability CVE-2024-27914: Information

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.

Published: March 18, 2024
Modified: March 18, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.14-alt110.0.15-alt1ALT-PU-2024-4487-1343562Fixed
glpisisyphus_e2k10.0.14-alt110.0.15-alt1ALT-PU-2024-4589-1-Fixed
glpisisyphus_loongarch6410.0.14-alt110.0.15-alt1ALT-PU-2024-4596-1-Fixed
glpip1010.0.14-alt110.0.15-alt1ALT-PU-2024-4750-2343937Fixed
glpip10_e2k10.0.14-alt110.0.15-alt1ALT-PU-2024-4884-1-Fixed
glpic10f110.0.15-alt110.0.15-alt1ALT-PU-2024-8030-2348513Fixed

References to Advisories, Solutions, and Tools