Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-11035
HistoryMay 05, 2020 - 10:15 p.m.

Cross site request forgery (csrf)

2020-05-0522:15:00
PRIOn knowledge base
www.prio-n.com
3

9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

CPENameOperatorVersion
fedoraeq31
fedoraeq32
glpige0.83.3
glpilt9.4.6

9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.3%