You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2024-07-03 14:05:00

francois-teclib
Expert GLPI
From: TECLIB
Registered: 2006-11-05
Posts: 75
Website

GLPI 10.0.16

This release fixes several security issues that has been recently discovered. Update is strongly recommended!

10.0.16-DOWNLOAD_GLPI-green.svg?logo=php&logoColor=white&style=for-the-badge?logo=php&logoColor=white&style=for-the-badge

You will find below the list of security issues fixed in this bugfixes version:

  • [SECURITY - high] Account takeover via SQL Injection in AJAX scripts (CVE-2024-37148)

  • [SECURITY - high] Remote code execution through the plugin loader (CVE-2024-37149)

  • [SECURITY - moderate] Authenticated file upload to restricted tickets (CVE-2024-37147)

Following the last releases of 10.0.16, a few annoying issues has been detected:

  • [[FIX] Freesize database field was not correctly migrated

  • [[FIX] Network inventoried stacked switches had all the same name

  • [[FIX] Remove monitors from inventory when no monitor is present

  • [[FIX] Import location hierarchy from LDAP and Inventory

  • Several minor fixes

See full technical changelog for details.

We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!


Besoin d'un support professionnel pour GLPI ? Pensez à GLPI Network ! https://glpi-project.org/fr/tarifs/

Connaissez-vous l'offre Cloud maintenue et supportée par l'équipe qui édite GLPI ?
Vous pouvez tester gratuitement pendant 45 jours ! https://glpi-network.cloud (ou plus si besoin)

Offline

Board footer

Powered by FluxBB