SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-27937

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

MEDIUM 4.3EPSS 27.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 27.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
27.14% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
glpi-project/glpi
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.