Une nouvelle version de GLPI est disponible.
This release fixes several critical security issues that has been recently discovered. Update is strongly recommended!
You can download the GLPI 10.0.2 archive on GitHub.
Exceptionally, as we have a critical security issue on an unauthenticated page, we also release a GLPI 9.5.8 archive.
You’ll find below the list of security issues fixed in this bugfixes version:
- [SECURITY] Unauthenticated SQL injection on login page (CVE-2022-31061)
- [SECURITY] SQL injection on actor part in assistance forms (CVE-2022-31056)
- [SECURITY] Unauthenticated Sensitive Data Exposure on Refused Inventory Files (CVE-2022-31068)
Voici également une courte liste des corrections de bugs importantes apportées à cette version :
- FIX adding actors to ITIL Objects (#11796, #11957)
- FIX unwanted “promote to ticket” feature on self-service interface (#11834)
- FIX native inventory do not inject switch information (#11864)
- FIX entity for software creation (#11887, #11837)
- FEAT permits global lock on entity (#11853)
Le journal des modifications complet est disponible pour plus de détails.
Nous tenons à remercier toutes les personnes qui ont contribué à cette nouvelle version et tous ceux qui contribuent régulièrement au projet GLPI !
Cordialement.
