11.0.10 and 10.0.28 releases fix several security issues that have been recently discovered. Update is strongly recommended!
Important note: with the upcoming release of GLPI 12.0.0, version 10.0.28 will be the final release of the 10.0 branch, which will no longer receive bugfixes.
Many bug fixes have also been made, read the changelogs for more details:
You can download the new archives on GitHub:
You will find below the list of security issues fixed in these bugfix versions:
- [SECURITY - High 10.0 & 11.0] Authorization bypass in massive actions
- [SECURITY - High 10.0 & 11.0] Privilege escalation via user cloning
- [SECURITY - High 11.0] SQL Injection through form actors dropdown
- [SECURITY - High 11.0] 2FA deactivation/modification on users with higher privileges
- [SECURITY - High 11.0] Reflected XSS in the dashboard search result widget
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
