Vulnerability CVE-2025-21626: Information

Description

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Published: Feb. 25, 2025
Modified: March 4, 2025
Error type identifier: CWE-200

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.18-alt110.0.18-alt1ALT-PU-2025-4052-1377585Fixed
glpisisyphus_e2k10.0.18-alt110.0.18-alt1ALT-PU-2025-4342-1-Fixed
glpisisyphus_riscv6410.0.18-alt110.0.18-alt1ALT-PU-2025-4139-1-Fixed
glpisisyphus_loongarch6410.0.18-alt110.0.18-alt1ALT-PU-2025-4148-1-Fixed
glpip1110.0.18-alt110.0.18-alt1ALT-PU-2025-4115-2377682Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      0.71
      End excluding
      10.0.18