Vulnerability CVE-2025-25192: Information
Description
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
Published: Feb. 25, 2025
Modified: March 18, 2025
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glpi | sisyphus | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4052-1 | 377585 | Fixed |
glpi | sisyphus_e2k | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4342-1 | - | Fixed |
glpi | sisyphus_riscv64 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4139-1 | - | Fixed |
glpi | sisyphus_loongarch64 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4148-1 | - | Fixed |
glpi | p11 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4115-2 | 377682 | Fixed |