Skip to content

10.0.10

Compare
Choose a tag to compare
@trasher trasher released this 25 Sep 08:43
· 457 commits to 10.0/bugfixes since this release

This is a security release, upgrading is recommended

Download it

This release fixes a security issue that has been recently discovered. Update is recommended!

You can download the GLPI 10.0.10 archive on GitHub.

You will find below security issues fixed in this bugfixes version:

  • [SECURITY - Critical] Unallowed PHP script execution (CVE-2023-42802).
  • [SECURITY - High] Account takeover via SQL Injection in UI layout preferences (CVE-2023-41320).
  • [SECURITY - High] Account takeover via Kanban feature (CVE-2023-41326).
  • [SECURITY - High] Account takeover through API (CVE-2023-41324).
  • [SECURITY - High] File deletion through document upload process (CVE-2023-42462).
  • [SECURITY - Moderate] Sensitive fields enumeration through API (CVE-2023-41321).
  • [SECURITY - Moderate] Privilege Escalation from technician to super-admin (CVE-2023-41322).
  • [SECURITY - Moderate] Users login enumeration by unauthenticated user (CVE-2023-41323).
  • [SECURITY - Moderate] Phishing through a login page malicious URL (CVE-2023-41888).
  • [SECURITY - Moderate] SQL injection in ITIL actors (CVE-2023-42461).

Also, here is a short list of main changes done in this version:

  • [FEATURE] PHP 8.3 and MySQL 8.1 support.
  • [FEATURE] Enable usage of images in rich text of followups/tasks/solution templates.
  • [PERFORMANCES] Improve ticket timeline rendering performances.
  • [FIX] Fix issues with usage of LDAP bind options.
  • [FIX] Fix some issues on SLA/OLA escalation levels computation.
  • [FIX] Fix some issues on search on numeric and dates fields.
  • Several minor fixes

The full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.