Impact
If a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorisation has already been established.
Patches
Upgrade to 10.0.18.
Workarounds
Disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Impact
If a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorisation has already been established.
Patches
Upgrade to 10.0.18.
Workarounds
Disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].