Vulnerabilities > CVE-2022-39234 - Insufficient Session Expiration vulnerability in Glpi-Project Glpi

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
glpi-project
CWE-613

Summary

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

Vulnerable Configurations

Part Description Count
Application
Glpi-Project
176

Common Weakness Enumeration (CWE)