High severity7.5NVD Advisory· Published May 5, 2020· Updated Jun 17, 2026
CVE-2020-11035
CVE-2020-11035
Description
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: >=0.83.3,<9.4.6
- (no CPE)range: <9.4.6
- (no CPE)range: > 0.83.3, < 9.4.6
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/glpi-project/glpi/security/advisories/GHSA-w7q8-58qp-vmpfnvdTechnical Description
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/nvd
News mentions
0No linked articles in our index yet.