UBUNTU-CVE-2023-34254
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-34254
Summary:
Details: The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the privileges it uses. In the case, the agent is running with administration privileges, a malicious user could gain high privileges on the computer glpi-agent is running on. A malicious user could also disclose all remote accesses the agent is configured with for remoteinventory task. This vulnerability has been patched in glpi-agent 1.5.
References: https://ubuntu.com/security/CVE-2023-34254, https://github.com/glpi-project/glpi-agent/security/advisories/GHSA-39vc-hxgm-j465, https://github.com/glpi-project/glpi-agent/blob/dd313ee0914becf74c0e48cb512765210043b478/Changes#L98, https://www.cve.org/CVERecord?id=CVE-2023-34254
Affected packages
Package
Name: glpi
Purl: pkg:deb/ubuntu/[email protected]+dfsg.1-1ubuntu1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
