This is a security release, upgrading is recommended
You will find below the list of security issues fixed in this bugfixes version:
- [SECURITY - High] Authorization bypass in massive actions
- [SECURITY - High] Privilege escalation via user cloning
- [SECURITY - High] Improper rights checks in users deletion
- [SECURITY - High] SQL Injection through form actors dropdown
- [SECURITY - High] 2FA deactivation/modification on users with higher privileges
- [SECURITY - High] Reflected XSS in the dashboard search result widget
- [SECURITY - Medium] Users names enumaration via the planning feature
- [SECURITY - Medium] Missing authorization checks in the planning feature
The full changelog is available for more details.
We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!
Regards.