FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

glpi -- bypass of the open redirect protection

Affected packages
glpi < 9.4.6

Details

VuXML ID 3a63f478-3b10-11eb-af2a-080027dbe4b7
Discovery 2020-03-30
Entry 2020-03-30

MITRE Corporation reports:

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

References

CVE Name CVE-2020-11034
URL https://github.com/glpi-project/glpi/security/advisories/GHSA-gxv6-xq9q-37hg
URL https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/
URL https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/