Skip to content

Leak of sensitive informations through login page error

Moderate
trasher published GHSA-6mmq-x3j2-677j Sep 14, 2022

Package

glpi (glpi-project)

Affected versions

>=9.5.0

Patched versions

10.0.3

Description

Impact

Exposure of private informations defined in setup of GLPI (like smtp or cas hosts)
Passwords are not exposed.

Patches

upgrade to 10.0.3

For more information

If you have any questions or comments about this advisory:

mail us at glpi-security@ow2.org

Severity

Moderate

CVE ID

CVE-2022-31143

Weaknesses

Credits