Medium severity6.8NVD Advisory· Published Sep 15, 2021· Updated Jun 17, 2026
CVE-2021-39213
CVE-2021-39213
Description
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: >=9.1,<9.5.6
- (no CPE)range: >=9.1,<9.5.6
- (no CPE)range: >= 9.1, < 9.5.6
Patches
Vulnerability mechanics
References
2- github.com/glpi-project/glpi/releases/tag/9.5.6nvdRelease NotesThird Party Advisory
- github.com/glpi-project/glpi/security/advisories/GHSA-6w9f-2m6g-5777nvdThird Party Advisory
News mentions
0No linked articles in our index yet.