Unrated severityNVD Advisory· Published Sep 15, 2021· Updated Aug 4, 2024
IP restriction on GLPI API Bypass with custom header injection
CVE-2021-39213
Description
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2>=9.1, <9.5.6+ 1 more
- (no CPE)range: >=9.1, <9.5.6
- (no CPE)range: >= 9.1, < 9.5.6
Patches
Vulnerability mechanics
References
2- github.com/glpi-project/glpi/releases/tag/9.5.6mitrex_refsource_MISC
- github.com/glpi-project/glpi/security/advisories/GHSA-6w9f-2m6g-5777mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.