Able to read any token through API user endpoint in GLPI
Published May 5, 2020
7.2
HIGHCVSS 3.1
EPSS 1.04%
Description
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete data normally non accessible to the current user. - All personal_tokens can display another users planning. Exploiting this vulnerability requires the api to be enabled, a technician account. It can be mitigated by adding an application token. This is fixed in version 9.4.6.
Affected products
-
- Version >9.1, < 9.4.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Glpi-Project | GLPI | n/a |
|
Configuration 1
- ≥ 9.1 · < 9.4.6
Configuration 2
- 31
- 32
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3418 Advisory
- https://github.com/glpi-project/glpi/security/advisories/GHSA-rf54-3r4w-4h55 x_refsource_CONFIRMVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/ vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3418 | Advisory | |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-rf54-3r4w-4h55 | x_refsource_CONFIRMVendor Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/ | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.