
Cloud Vulnerability DB
A community-led vulnerabilities database
The GLPI Agent, a generic management agent, contained a critical vulnerability (CVE-2023-34254) prior to version 1.5. The vulnerability was discovered in the remoteinventory task when running against Unix platforms using SSH command mode. The issue was disclosed on June 21, 2023, and affects all versions of GLPI Agent before version 1.5 (NIST NVD, GitHub Advisory).
The vulnerability is classified as a command injection flaw (CWE-78) with a CVSS v3.1 base score of 7.2 HIGH (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). The issue occurs when the agent runs the remoteinventory task against a Unix platform using SSH command mode, where an administrator user on the remote system can inject commands into a specific workflow that the agent executes with its privileges (NIST NVD).
The vulnerability has significant impact potential. If the GLPI Agent is running with administrative privileges, a malicious user could gain elevated privileges on the computer where GLPI Agent is running. Additionally, attackers could potentially disclose all remote access configurations that the agent uses for the remoteinventory task (GitHub Advisory).
The vulnerability requires an attacker to have administrator access on the remote Unix system being inventoried. While this presents a high privilege requirement, the attack complexity is considered low once these privileges are obtained (NIST NVD).
The primary mitigation is to upgrade to GLPI Agent version 1.5 or later. For users unable to upgrade immediately, there are two workarounds: 1) Force remoteinventory mode to libssh2 by adding ?mode=libssh2 to the remote URL, or 2) Disable the vulnerable code by setting no-category configuration to process,virtualmachine,video,drive,database,storage (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."