Bug 847145 (CVE-2012-4002, CVE-2012-4003) - CVE-2012-4002 CVE-2012-4003 glpi: XSS and CSRF flaws fixed in in 0.83.3
Summary: CVE-2012-4002 CVE-2012-4003 glpi: XSS and CSRF flaws fixed in in 0.83.3
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-4002, CVE-2012-4003
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-08-09 20:55 UTC by Vincent Danen
Modified: 2021-10-19 21:56 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-19 21:56:14 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2012-08-09 20:55:00 UTC
Upstream released GLPI 0.83.3 [1] which fixes a CSRF flaw (CVE-2012-4002) [2],[3] fixed in r18770 [4]  and some XSS flaws (CVE-2012-4003) [4].

Patches are referenced in the noted bug reports.

[1] https://forge.indepnet.net/projects/glpi/versions/771
[2] https://forge.indepnet.net/issues/3704
[3] https://forge.indepnet.net/issues/3707
[4] https://forge.indepnet.net/issues/3705


Note You need to log in before you can comment on or make changes to this bug.