Skip to content

IP restriction on GLPI API Bypass with custom header injection

Moderate
trasher published GHSA-6w9f-2m6g-5777 Sep 15, 2021

Package

glpi (glpi)

Affected versions

>= 9.1

Patched versions

9.5.6

Description

Impact

Every GLPI with API Rest enabled (added in 9.1 version)

Patches

Upgrade to 9.5.6

Workarounds

Disable API Rest

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-39213

Weaknesses

No CWEs