PT-2021-14424 · Glpi+1 · Glpi+1

·

CVE-2021-21327

·

Published

2021-03-08

·

Updated

2024-05-22

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.5.4
Description The issue allows a non-authenticated user to remotely instantiate objects of any class in the GLPI environment, potentially leading to malicious attacks or the start of a "POP chain". This affects the integrity of the GLPI core platform and third-party plugins runtime, particularly those with sensitive operations in their constructors or destructors.
Recommendations For versions prior to 9.5.4, update to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive classes and their constructors or destructors to minimize the risk of exploitation.

Exploit

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1583
ALT-PU-2021-1660
ALT-PU-2024-8094
CVE-2021-21327
GHSA-QMW7-W2M4-RJWP

Affected Products

Alt Linux
Glpi