Bug 1882105 (CVE-2020-11031) - CVE-2020-11031 glpi: encryption algorithm used is insecure
Summary: CVE-2020-11031 glpi: encryption algorithm used is insecure
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2020-11031
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1882106 1882107
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-09-23 19:16 UTC by Guilherme de Almeida Suckevicz
Modified: 2020-09-23 20:41 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-09-23 20:41:08 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-09-23 19:16:46 UTC
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library chosen is sodium.

Reference:
https://github.com/glpi-project/glpi/security/advisories/GHSA-7xwm-4vjr-jvqh

Upstream patch:
https://github.com/glpi-project/glpi/commit/f1ae6c8481e5c19a6f1801a5548cada45702e01a#diff-b5d0ee8c97c7abd7e3fa29b9a27d1780

Comment 1 Guilherme de Almeida Suckevicz 2020-09-23 19:17:04 UTC
Created glpi tracking bugs for this issue:

Affects: epel-7 [bug 1882106]
Affects: fedora-all [bug 1882107]

Comment 2 Product Security DevOps Team 2020-09-23 20:41:08 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.