This is a security release, upgrading is recommended
This release fixes a few security issues that have been recently discovered. Update is recommended!
You will find below the list of security issues fixed in this bugfixes version:
- [SECURITY - High] Upload of malicious page on the web-server
- [SECURITY - High] Unauthenticated SQL injection in planning feature
- [SECURITY - High] Unexpected X509 authentication success with unverified certificated
- [SECURITY - High] Race condition in marketplace allowing malicious plugin installation
- [SECURITY - High] Arbitrary files deletion during documents creation
- [SECURITY - Medium] Unexpected access to followups/tasks/solutions generated from templates
- [SECURITY - Medium] Unauthorized visibility expansion of knowbase items, reminders and RSS feed
Many bug fixes have also been made, read the full changelog is available for more details.
We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!
Regards.