Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32298 | GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subject to server-side request forgery (SSRF). In case the remote address is not a valid RSS feed, an RSS autodiscovery feature is triggered. This feature does not check safety or URLs. Versions 9.5.13 and 10.0.7 contain a patch for this issue. |
Mon, 10 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-10T16:37:09.581Z
Reserved: 2023-03-20T12:19:47.207Z
Link: CVE-2023-28633
Updated: 2024-08-02T13:43:23.320Z
Status : Modified
Published: 2023-04-05T16:15:08.040
Modified: 2024-11-21T07:55:42.437
Link: CVE-2023-28633
No data.
OpenCVE Enrichment
No data.
EUVD