CVE-2020-11033
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete data normally non accessible to the current user. - All personal_tokens can display another users planning. Exploiting this vulnerability requires the api to be enabled, a technician account. It can be mitigated by adding an application token. This is fixed in version 9.4.6.
Affected (3)
Products: Glpi Project: Glpi · Fedoraproject: Fedora
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.1 to 9.4.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 31 |
References (6)
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.