Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-B3695B08-3B3A-11EB-AF2A-080027DBE4B7 (CVE-2020-5248): glpi -- Public GLPIKEY can be used to decrypt any data

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-B3695B08-3B3A-11EB-AF2A-080027DBE4B7 (CVE-2020-5248): glpi -- Public GLPIKEY can be used to decrypt any data

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
01/02/2020
Created
12/14/2020
Added
12/12/2020
Modified
12/12/2020

Description

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing instances, data must be reencrypted with the new key. Problem is we can not know which columns or rows in the database are using that; espcially from plugins. Changing the key without updating data would lend in bad password sent from glpi; but storing them again from the UI will work.

Solution(s)

  • freebsd-upgrade-package-glpi

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;