The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.
History

Tue, 25 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
Description The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.
Title GLPI Inventory plugin has Improper Access Control Vulnerability
Weaknesses CWE-22
CWE-552
CWE-73
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-25T14:40:39.830Z

Reserved: 2025-02-19T16:30:47.778Z

Link: CVE-2025-27147

cve-icon Vulnrichment

Updated: 2025-03-25T14:40:36.100Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-25T15:15:24.957

Modified: 2025-03-27T16:45:46.410

Link: CVE-2025-27147

cve-icon Redhat

No data.