Vulnerability Description
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | < 9.5.6 |
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/releases/tag/9.5.6Release NotesThird Party Advisory
- https://github.com/glpi-project/glpi/security/advisories/GHSA-hwxq-4c5f-m4v2Third Party Advisory
- https://huntr.dev/bounties/b2e99a41-b904-419f-a274-ae383e4925f2/Third Party Advisory
- https://github.com/glpi-project/glpi/releases/tag/9.5.6Release NotesThird Party Advisory
- https://github.com/glpi-project/glpi/security/advisories/GHSA-hwxq-4c5f-m4v2Third Party Advisory
- https://huntr.dev/bounties/b2e99a41-b904-419f-a274-ae383e4925f2/Third Party Advisory
FAQ
What is CVE-2021-39210?
CVE-2021-39210 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts...
How severe is CVE-2021-39210?
CVE-2021-39210 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-39210?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi-Project Glpi.