A new GLPI version is available!
This release fixes a few security issues that have been recently discovered. Update is recommended!
You can download the GLPI 10.0.13 archive on GitHub.
Vous trouverez ci-dessous la liste des problèmes de sécurité corrigés dans cette version corrective :
- [SECURITY - high] SQL Injection in through the search engine (CVE-2024-27096)
- [SECURITY - moderate] Blind SSRF using Arbitrary Object Instantiation (CVE-2024-27098)
- [SECURITY - moderate] Stored XSS in dashboards (CVE-2024-27104)
- [SECURITY - moderate] Reflected XSS in debug mode (CVE-2024-27914)
- [SECURITY - moderate] Sensitive fields access through dropdowns (CVE-2024-27930)
- [SECURITY - moderate] Users emails enumeration (CVE-2024-27937)
Also, here is a short list of main changes done in this version:
- [FIX] Error when creating a Ticket with SLA/OLA.
- [FIX] Weekly recurrent reservations creation does not work.
Le journal des modifications complet est disponible pour plus de détails.
Nous tenons à remercier toutes les personnes qui ont contribué à cette nouvelle version et tous ceux qui contribuent régulièrement au projet GLPI !
Cordialement.
