CVE-2024-53850

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53850
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53850.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-53850
Aliases
  • GHSA-fw42-79gw-7qr9
Published
2024-12-26T21:41:55Z
Modified
2025-10-14T14:34:11Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L CVSS Calculator
Summary
The Addressing GLPI plugin allows data enumeration through uncontrolled object instantiation
Details

The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with 3.0.0 and before 3.0.3, a poor security check allows an unauthenticated attacker to determine whether data exists (by name) in GLPI.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_versions

[
    {
        "type": "",
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": ">= 3.0.0 < 3.0.3"
            }
        ]
    }
]