Пакет glpi: Информация

  • Default inline alert: Версия в репозитории: 10.0.15-alt1

Исходный пакет: glpi
Версия: 10.0.5-alt1
Собран:  6 ноября 2022 г. 14:02
Категория: Сети/Прочее
Сообщить об ошибке в пакете
Домашняя страница: http://www.glpi-project.org

Лицензия: GPLv3
О пакете: IT and asset management software
Описание: 
GLPI is the Information Resource-Manager with an additional Administration-
Interface.
You can use it to build up a database with an inventory for your company
(computer, software, printers...).
It has enhanced functions to make the daily life for the administrators easier,
like a job-tracking-system with mail-notification and methods to build a
database with basic information about your network-topology.

Список rpm-пакетов, предоставляемых данным srpm-пакетом:
glpi (noarch)
glpi-apache2 (noarch)
glpi-php7 (noarch)
glpi-php8.0 (noarch)
glpi-php8.1 (noarch)

Сопровождающий: Pavel Zilke

Список участников:
Pavel Zilke

    1. rpm-macros-webserver-common

Последнее изменение


4 ноября 2022 г. Pavel Zilke 10.0.5-alt1
- New version 10.0.4
- This release fixes several security issues that has been recently discovered. Update is recommended!
- Security fixes:
 + CVE-2022-39276 : Blind SSRF in RSS feeds and planning
 + CVE-2022-39372 : Stored XSS in user information
 + CVE-2022-39373 : Stored XSS in entity name
 + CVE-2022-39376 : Improper input validation on emails links
 + CVE-2022-39370 : Improper access to debug panel
 + CVE-2022-39234 : User's session persist after permanently deleting his account
 + CVE-2022-39262 : Stored XSS on login page
 + CVE-2022-39277 : XSS in external links
 + CVE-2022-39375 : XSS through public RSS feed
 + CVE-2022-39323 : SQL Injection on REST API
 + CVE-2022-39371 : Stored XSS through asset inventory
14 сентября 2022 г. Pavel Zilke 10.0.3-alt1
- New version 10.0.3
- This release fixes several critical security issues that has been recently discovered. Update is strongly recommended!
- Security fixes:
 + CVE-2022-35945 : XSS through registration API
 + CVE-2022-31143 : Leak of sensitive information through login page error
 + CVE-2022-31187 : Stored XSS through global search (CVE-2022-31187)
 + CVE-2022-35914 : [critical] Command injection using a third-party library script
 + CVE-2022-35946 : SQL injection through plugin controller
 + CVE-2022-35947 : [critical] Authentication via SQL injection
 + CVE-2022-36112 : Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning
22 июля 2022 г. Pavel Zilke 10.0.2-alt1
- New version 10.0.2
- This is a security release, upgrading is recommended
- Security fixes:
 + CVE-2022-31061 : Unauthenticated SQL injection on login page
 + CVE-2022-31056 : SQL injection on actor part in assistance forms
 + CVE-2022-31068 : Unauthenticated Sensitive Data Exposure on Refused Inventory Files