Lucene search

K
osvGoogleOSV:CVE-2020-11035
HistoryMay 05, 2020 - 10:15 p.m.

CVE-2020-11035

2020-05-0522:15:12
Google
osv.dev
5

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.3%