High severity7.2NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026
CVE-2020-5248
CVE-2020-5248
Description
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing instances, data must be reencrypted with the new key. Problem is we can not know which columns or rows in the database are using that; espcially from plugins. Changing the key without updating data would lend in bad password sent from glpi; but storing them again from the UI will work.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: <9.4.6
- (no CPE)range: <9.4.6
- (no CPE)range: < 9.4.6
Patches
Vulnerability mechanics
References
2- github.com/glpi-project/glpi/commit/efd14468c92c4da43333aa9735e65fd20cbc7c6cnvdPatchThird Party Advisory
- github.com/glpi-project/glpi/security/advisories/GHSA-j222-j9mf-h6j9nvdMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.