You are not logged in.
Pages: 1
This release fixes several critical security issues that has been recently discovered. Update is strongly recommended!
You will find below the list of security issues fixed in this bugfixes version:
[SECURITY - Low] Blind SSRF in RSS feeds and planning (CVE-2022-39276)
[SECURITY - Low] Stored XSS in user information (CVE-2022-39372)
[SECURITY - Low] Stored XSS in entity name (CVE-2022-39373)
[SECURITY - Low] Improper input validation on emails links (CVE-2022-39376)
[SECURITY - Moderate] Improper access to debug panel (CVE-2022-39370)
[SECURITY - Moderate] User's session persist after permanently deleting his account (CVE-2022-39234)
[SECURITY - Moderate] Stored XSS on login page (CVE-2022-39262)
[SECURITY - Moderate] XSS in external links (CVE-2022-39277)
[SECURITY - Moderate] XSS through public RSS feed (CVE-2022-39375)
[SECURITY - High] SQL Injection on REST API (CVE-2022-39323)
[SECURITY - High] Stored XSS through asset inventory (CVE-2022-39371)
Also, here is a short list of main changes done in this version:
[FIX] Increase significantly dashboards performance
[FIX] Several bugs on images pasting
[FIX] Fixed and improved inventory locks management
[FIX] Display of printer cartridges
[FIX] Display and hide actors tooltips in tickets
[FIX] Improve display of headers above forms
[FIX] Move breakpoints on responsive displays
[SECURITY] Inventory API is now disabled by default
[FEATURE] Dedicated rights has been added for inventory
See full technical changelog for details.
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
Besoin d'un support professionnel pour GLPI ? Pensez à GLPI Network ! https://glpi-project.org/fr/tarifs/
Connaissez-vous l'offre Cloud maintenue et supportée par l'équipe qui édite GLPI ?
Vous pouvez tester gratuitement pendant 45 jours ! https://glpi-network.cloud (ou plus si besoin)
Offline
Pages: 1