Use of a broken or risky cryptographic algorithm in GLPI - CVE-2020-11031

 

Use of a broken or risky cryptographic algorithm in GLPI - CVE-2020-11031

Published: July 7, 2020 / Updated: May 4, 2026


Vulnerability identifier: #VU129533
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11031
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to a weak encryption algorithm in the encryption mechanism when protecting stored data with user-supplied passwords. A remote attacker can use a weak or predictable password to decrypt protected data and disclose sensitive information.

The security of encrypted data depends on the strength of the password chosen by the user.


Affected software

GLPI

How to mitigate CVE-2020-11031

Install security update from vendor's website.

GLPI - update to 9.5.0

External References

Related Security Bulletins