Two new GLPI versions are now available!
We've just released GLPI 11.0.9 and GLPI 10.0.27 to patch several critical security vulnerabilities.
We strongly advise upgrading your instances as soon as possible!
GLPI 11.0.9 changelog: https://github.com/glpi-project/glpi/milestone/91?closed=1
GLPI 10.0.27 changelog: https://github.com/glpi-project/glpi/milestone/90?closed=1
Get the updates here: https://github.com/glpi-project/glpi/releases
You will find below the list of security issues fixed in theses bugfixes versions:
- [SECURITY - High 11.0] XSS via form illustration import
- [SECURITY - High 10.0 & 11.0] Upload of malicious page on the web-server
- [SECURITY - High 10.0 & 11.0] Unauthenticated SQL injection in planning feature
- [SECURITY - High 10.0 & 11.0] Unexpected X509 authentication success with unverified certificated
- [SECURITY - High 10.0 & 11.0] Race condition in marketplace allowing malicious plugin installation
- [SECURITY - Medium 10.0 & 11.0] Unexpected access to followups/tasks/solutions generated from templates
Important note:
Over the coming months, we will be increasing our release frequency to keep up with the current influx of security reports.
Like other popular open-source projects—and with the rise of LLMs and agent-driven pentesting—we have seen a significant surge in report volume. As an open-source project, we are doing our best to manage this wave efficiently and keep the platform secure.
On your end, please expect security releases roughly every two weeks.
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
