Unrated severityNVD Advisory· Published Sep 15, 2021· Updated Aug 4, 2024
IP restriction on GLPI API Bypass with custom header injection
CVE-2021-39213
Description
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.
Affected products
1- Range: >= 9.1, < 9.5.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/glpi-project/glpi/releases/tag/9.5.6mitrex_refsource_MISC
- github.com/glpi-project/glpi/security/advisories/GHSA-6w9f-2m6g-5777mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.