CVE-2020-11031: falha de alta gravidade em glpi-project GLPI
Insecure encryption algorithm in GLPI
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.3%
probabilidade de exploração
0.3%top 76% das CVEs
exploração observada
nãonenhuma fonte reporta
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library chosen is sodium.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Produtos afetados
glpi-project · GLPICVEs relacionadas — glpi-project GLPI
No mesmo produto, das mais perigosas para as menos.
CVE-2020-11060HIGHRemote Code Execution in GLPIEPSS 10.9%CVE-2020-11034MEDIUMbypass of manageRedirect in GLPIEPSS 7.6%CVE-2020-11033MEDIUMAble to read any token through API user endpoint in GLPIEPSS 1.0%CVE-2020-11032HIGHSQL injection on addme_observer and addme_assign in GLPIEPSS 1.0%CVE-2020-11036HIGHXSS in GLPIEPSS 0.8%CVE-2020-11035HIGHweak CSRF tokens in GLPIEPSS 0.8%