Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with user_token on API Rest. https://github.com/glpi-project/glpi/security/advisories/GHSA-cp6q-9p4x-8hr9
Created glpi tracking bugs for this issue: Affects: epel-all [bug 2139924]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.