Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-31143: Do not expose CFG_GLPI on anonymous page · glpi-project/glpi@e66a0df

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. It was found that in affected versions there is an exposure of private information defined in setup of GLPI (like smtp or cas hosts). Note that passwords are not exposed. Users are advised to upgrade to version 10.0.3. There are no known workarounds for this issue.

CVE
#redis

@@ -0,0 +1,57 @@

{#

# ---------------------------------------------------------------------

# GLPI - Gestionnaire Libre de Parc Informatique

# http://glpi-project.org

# @copyright 2015-2022 Teclib’ and contributors.

# @copyright 2003-2014 by the INDEPNET Development Team.

# @licence https://www.gnu.org/licenses/gpl-3.0.html

# ---------------------------------------------------------------------

# LICENSE

# This file is part of GLPI.

# This program is free software: you can redistribute it and/or modify

# it under the terms of the GNU General Public License as published by

# the Free Software Foundation, either version 3 of the License, or

# (at your option) any later version.

# This program is distributed in the hope that it will be useful,

# but WITHOUT ANY WARRANTY; without even the implied warranty of

# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the

# GNU General Public License for more details.

# You should have received a copy of the GNU General Public License

# along with this program. If not, see https://www.gnu.org/licenses/.

# ---------------------------------------------------------------------

#}

{% extends ‘layout/page_card_notlogged.html.twig’ %}

{% block content_block %}

<div class="alert alert-warning">

<div class="d-flex align-items-center">

<div class="me-4">

<i class="ti ti-alert-triangle fa-2x"></i>

</div>

<div>

<h4 class="alert-title">

{{ __(“Error”) }}

</h4>

<div>

{{ error }}

</div>

<a href="{{ login_url }}" class="btn btn-primary mt-3">

<i class="ti ti-login"></i>

<span>{{ __(‘Log in again’) }}</span>

</a>

</div>

</div>

</div>

{% endblock %}

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907