← Back

CVE-2020-11035

nvd nist
Published: May 5, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.7
Source: NVD

Description

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

Affected (3)

1 product
Glpi
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.83.3 to 9.4.6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32

Timeline

No history available yet.