CVE-2021-21255

NameCVE-2021-21255
DescriptionGLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glpi (PTS)jessie0.84.8+dfsg.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glpisourcejessie(unfixed)end-of-life
glpisource(unstable)(unfixed)unimportant

Notes

Only supported behind an authenticated HTTP zone
https://github.com/glpi-project/glpi/security/advisories/GHSA-v3m5-r3mx-ff9j
https://github.com/glpi-project/glpi/commit/aade65b7f67d46f23d276a8acb0df70651c3b1dc

Search for package or bug name: Reporting problems