Сопровождающий Pavel Zilke в ветке p10: Информация
Имя сопровождающего: Pavel Zilke (zidex)
Собрано source пакетов в данной ветке: 4
Последние изменения
25 июля 2024 г. 15:11
#352991 отправлено Pavel Zilke
security_fix
IT and asset management software
3 июля 2024 г. Pavel Zilke:
- New version 10.0.16 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-37148 : Account takeover via SQL Injection in AJAX scripts + CVE-2024-37149 : Remote code execution through the plugin loader + CVE-2024-37147 : Authenticated file upload to restricted tickets
2 мая 2024 г. 17:50
#347218 отправлено Pavel Zilke
security_fix
IT and asset management software
26 апреля 2024 г. Pavel Zilke:
- New version 10.0.15 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-31456 Authenticated SQL injection from map search + CVE-2024-29889 Account takeover via SQL Injection in saved searches feature
1 апреля 2024 г. 17:01
#343937 отправлено Pavel Zilke
security_fix
IT and asset management software
25 марта 2024 г. Pavel Zilke:
- New version 10.0.14 - Due to a few regressions in the last (10.0.13), an early release is available.
20 февраля 2024 г. 16:13
#340950 отправлено Pavel Zilke
security_fix
IT and asset management software
2 февраля 2024 г. Pavel Zilke:
- New version 10.0.12 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2024-23645 : Reflected XSS in reports pages + CVE-2023-51446 : LDAP Injection during authentication ()
21 декабря 2023 г. 12:37
#336743 отправлено Pavel Zilke
fix_48856
IT and asset management software
19 декабря 2023 г. Pavel Zilke:
- Fix spec (ALT #48856)
18 декабря 2023 г. 21:34
#336575 отправлено Pavel Zilke
security_fix
IT and asset management software
14 декабря 2023 г. Pavel Zilke:
- New version 10.0.11 - This release fixes a security issue that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-43813 : Authenticated SQL Injection + CVE-2023-46727 : SQL injection through inventory agent request + CVE-2023-46726 : Remote code execution from LDAP server configuration form on PHP 7.4 - Deleted glpi-php8.0
2 июня 2023 г. 17:09
#322040 отправлено Pavel Zilke
security_fix
IT and asset management software
27 мая 2023 г. Pavel Zilke:
- New version 9.5.13 - This release fixes several security issues that have been recently discovered. Update is recommended! - Security fixes: + CVE-2023-28632 : Account takeover by authenticated user + CVE-2023-28838 : SQL injection through dynamic reports + CVE-2023-28852 : Stored XSS through dashboard administration + CVE-2023-28636 : Stored XSS on external links + CVE-2023-28639 : Reflected XSS in search pages + CVE-2023-28634 : Privilege Escalation from technician to super-admin + CVE-2023-28633 : Blind Server-Side Request Forgery (SSRF) in RSS feeds
22 марта 2023 г. 16:11
#316955 отправлено Pavel Zilke
security_fix
IT and asset management software
18 марта 2023 г. Pavel Zilke:
- New version 9.5.12 - This release fixes several security issues that has been recently discovered. Update is recommended! - Security fixes: + CVE-2023-22722 : XSS on browse views + CVE-2023-22725 : XSS on external links + CVE-2023-23610 : Unauthorized access to data export + CVE-2022-41941 : Stored XSS inside Standard Interface Help Link href attribute
14 ноября 2022 г. 20:57
#309550 отправлено Pavel Zilke
security_fix
IT and asset management software
5 ноября 2022 г. Pavel Zilke:
- New version 9.5.11 - Bugfix for previouys release
16 сентября 2022 г. 17:19
#306811 отправлено Pavel Zilke
critical_security_fix
IT and asset management software
14 сентября 2022 г. Pavel Zilke:
- New version 9.5.9 - This release fixes several critical security issues that has been recently discovered. Update is strongly recommended! - Security fixes: + CVE-2022-35945 : XSS through registration API + CVE-2022-31143 : Leak of sensitive information through login page error + CVE-2022-35914 : [critical] Command injection using a third-party library script + CVE-2022-35946 : SQL injection through plugin controller + CVE-2022-35947 : [critical] Authentication via SQL injection + CVE-2022-36112 : Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
7 июля 2022 г. 12:16
#303183 отправлено Pavel Zilke
security_fix
IT and asset management software
4 июля 2022 г. Pavel Zilke:
- New version 9.5.8 - This is a security release, upgrading is recommended - Security fixes: + CVE-2022-31061 : SQL injection on login page + CVE-2022-24868 : XSS / open redirect via SVG file upload + CVE-2022-24869 : Cross Site CSS Injection
18 марта 2022 г. 21:57
#296717 отправлено Pavel Zilke
security_fix
IT and asset management software
27 января 2022 г. Pavel Zilke:
- New version 9.5.7 - This is a security release, upgrading is recommended - Security fixes: + CVE-2022-21720 : SQL injection using custom CSS administration form + CVE-2022-21719 : Reflected XSS using reload button
14 октября 2021 г. 19:08
#287043 отправлено Pavel Zilke
security_fix
IT and asset management software
12 октября 2021 г. Pavel Zilke:
- New version 9.5.6 - This is a security release, upgrading is recommended - Security fixes: + CVE-2021-39211 : Disclosure of GLPI and server informations in telemetry endpoint + CVE-2021-39210 : Autologin cookie accessible by scripts + CVE-2021-39209 : Bypassable CSRF protection on ajax endpoints + CVE-2021-39213 : Bypassable IP restriction on GLPI API using custom header injection