| Vulnerability Name: | CVE-2022-39234 (CCN-241024) | ||||||||||||
| Assigned: | 2022-11-03 | ||||||||||||
| Published: | 2022-11-03 | ||||||||||||
| Updated: | 2022-11-04 | ||||||||||||
| Summary: | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds. | ||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.5 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-613 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2022-39234 Source: XF Type: UNKNOWN glpi-cve202239234-info-disc(241024) Source: CCN Type: GLPI GIT Repository User's session persist after permanently deleting his account | ||||||||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||