Vulnerability CVE-2025-23046: Information

Description

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorization has already been established. Version 10.0.18 contains a patch. As a workaround, one may disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: Feb. 25, 2025
Modified: Feb. 28, 2025
Error type identifier: CWE-303

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.18-alt110.0.18-alt1ALT-PU-2025-4052-1377585Fixed
glpisisyphus_e2k10.0.18-alt110.0.18-alt1ALT-PU-2025-4342-1-Fixed
glpisisyphus_riscv6410.0.18-alt110.0.18-alt1ALT-PU-2025-4139-1-Fixed
glpisisyphus_loongarch6410.0.18-alt110.0.18-alt1ALT-PU-2025-4148-1-Fixed
glpip1110.0.18-alt110.0.18-alt1ALT-PU-2025-4115-2377682Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      9.5.0
      End excluding
      10.0.18