Due to an undetected regression, GLPI 11.0.10 crashes when loading some plugins. Version 11.0.11 has been released to address the issue. We recommend that all users upgrade as soon as possible.
As a reminder, here are the details of version 11.0.10, which also apply to 11.0.11:
Many bug fixes have also been made, read the changelogs for more details:
You will find below the list of security issues fixed in this bugfix version:
- [SECURITY - High] Authorization bypass in massive actions
- [SECURITY - High] Privilege escalation via user cloning
- [SECURITY - High] Improper rights checks in users deletion
- [SECURITY - High] SQL Injection through form actors dropdown
- [SECURITY - High] 2FA deactivation/modification on users with higher privileges
- [SECURITY - High] Reflected XSS in the dashboard search result widget
- [SECURITY - Medium] Users names enumeration via the planning feature
- [SECURITY - Medium] Missing authorization checks in the planning feature
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
