A new GLPI version is available!
This release fixes a few security issues that have been recently discovered. The update is recommended!
You can download the GLPI 10.0.16 archive on GitHub.
Vous trouverez ci-dessous la liste des problèmes de sécurité corrigés dans cette version corrective :
- [SECURITY - high] Account takeover via SQL Injection in AJAX scripts (CVE-2024-37148)
- [SECURITY - high] Remote code execution through the plugin loader (CVE-2024-37149)
- [SECURITY - moderate] Authenticated file upload to restricted tickets (CVE-2024-37147)
Also, here is a short list of the main changes done in this version:
- [FIX] Freesize database field was not correctly migrated
- [FIX] Network inventoried stacked switches had all the same name
- [FIX] Remove monitors from inventory when no monitor is present
- [FIX] Import location hierarchy from LDAP and Inventory
Le journal des modifications complet est disponible pour plus de détails.
Nous tenons à remercier toutes les personnes qui ont contribué à cette nouvelle version et tous ceux qui contribuent régulièrement au projet GLPI !
Cordialement.
