Critical and high advisories are published one month after the release. All other advisories are published one week after the fix release.
If you found a security issue, please send an email to [glpi-security AT ow2.org].
You should provide us all details about the issue and the way to reproduce it. You may also provide a script that can be used to check the issue exists. Please also ensure the issue can really be exploited.
Once the report will be handled, and if the issue is not yet fixed (or in progress) we'll add it to the GitHub security tab, and add you as observer. Meanwhile, you will reserve a CVE for the issue.
Thank you for improving the security of glpi.
| Version | Supported |
|---|---|
| 11.0.x | ✔️ |
| 10.0.x | ✔️ |
| 9.5.x | ❌ |
| 9.4.x | ❌ |
| 9.3.x | ❌ |
| 9.2.x | ❌ |
| < 9.2 | ❌ |