View | Details | Raw Unified | Return to bug 278642
Collapse All | Expand All

(-)b/security/vuxml/vuln/2024.xml (+31 lines)
Lines 1-3 Link Here
1
  <vuln vid="5da8b1e6-0591-11ef-9e00-080027957747">
2
    <topic>GLPI -- multiple vulnerabilities</topic>
3
    <affects>
4
      <package>
5
	<name>glpi</name>
6
	<range><lt>10.0.15,1</lt></range>
7
      </package>
8
    </affects>
9
    <description>
10
	<body xmlns="http://www.w3.org/1999/xhtml">
11
	<p>GLPI team reports:</p>
12
	<blockquote cite="https://github.com/glpi-project/glpi/releases/tag/10.0.15">
13
	  <p>GLPI 10.0.15 Changelog</p>
14
	  <ul>
15
	    <li>[SECURITY - high] Authenticated SQL injection from map search (CVE-2024-31456)</li>
16
	    <li>[SECURITY - high] Account takeover via SQL Injection in saved searches feature (CVE-2024-29889)</li>
17
	  </ul>
18
	</blockquote>
19
	</body>
20
    </description>
21
    <references>
22
      <cvename>CVE-2024-31456</cvename>
23
      <cvename>CVE-2024-29889</cvename>
24
      <url>https://github.com/glpi-project/glpi/releases/tag/10.0.15</url>
25
    </references>
26
    <dates>
27
      <discovery>2024-04-03</discovery>
28
      <entry>2024-04-28</entry>
29
    </dates>
30
  </vuln>
31
1
  <vuln vid="b3affee8-04d1-11ef-8928-901b0ef714d4">
32
  <vuln vid="b3affee8-04d1-11ef-8928-901b0ef714d4">
2
    <topic>py-social-auth-app-django -- Improper Handling of Case Sensitivity</topic>
33
    <topic>py-social-auth-app-django -- Improper Handling of Case Sensitivity</topic>
3
    <affects>
34
    <affects>

Return to bug 278642