
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-11033 is a security vulnerability discovered in GLPI (IT asset management software) affecting versions since 9.1. The vulnerability was disclosed on May 5, 2020, and allows any API user with READ permissions on the User itemtype to access sensitive information when querying apirest.php/User endpoint (GitHub Advisory).
The vulnerability exists in the API endpoint response which exposes all api_tokens and personal_tokens when querying the User endpoint. This exposure occurs even with basic READ permissions on the User itemtype. The issue requires the API to be enabled and a technician account to exploit (GitHub Advisory).
The exposure of api_tokens can lead to privilege escalation and unauthorized access to read, update, or delete data that would normally be inaccessible to the current user. Additionally, exposed personal_tokens can be used to view other users' planning information (GitHub Advisory).
The vulnerability requires an attacker to have API access and a technician account with READ permissions on the User itemtype. The exploitation is straightforward once these conditions are met, as it only requires querying the apirest.php/User endpoint (GitHub Advisory).
The vulnerability was patched in GLPI version 9.4.6. For systems that cannot immediately update, several workarounds are available: disable the API functionality, disable user READ permissions for affected profiles, or add temporary app tokens to prevent users from testing the API without knowing the application token. The fix was implemented in commit 9f1117d (GitHub Advisory, Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."