CVE-2021-21327 MEDIUM

CVE-2021-21327: Unsafe Reflection in getItemForItemtype()

Vendor Glpi-Project
Product glpi
Weakness CWE-862 · Missing authorization
Published March 8, 2021
Last update August 3, 2024

CVSS base score

6.8/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious attacks, or to start a “POP chain”. As an example of direct impact, this vulnerability affects integrity of the GLPI core platform and third-party plugins runtime misusing classes which implement some sensitive operations in their constructors or destructors. This is fixed in version 9.5.4.

Key dates

02Disclosure timeline

March 8, 2021 CVE published
August 3, 2024 Record updated