Critical and high advisories are published one month after the release. All other advisories are published one week after the fix release.
If you found a security issue, please open an advisory on github.
If you do not have a github account, or if you want to contact us regarding a security issue, you can drop a mail to [glpi-security AT ow2.org].
You should provide us all details about the issue and the way to reproduce it. You may also provide a script that can be used to check the issue exists.
Once the report will be handled, and if the issue is not yet fixed (or in progress) we'll add it to the GitHub security tab, and add you as observer. Meanwhile, you will reserve a CVE for the issue.
Thank you for improving the security of glpi.
Version | Supported |
---|---|
10.0.x | ✔️ |
9.5.x | ❌ |
9.4.x | ❌ |
9.3.x | ❌ |
9.2.x | ❌ |
< 9.2 | ❌ |