New exclusive GLPI plugin: GLPI-AI

We would like to announce a new exclusive GLPI Network plugin — GLPI-AI — Available at https://plugins.glpi-project.org/#/plugin/glpiai. It is now available for clients with a GLPI Network subscription (Basic, Standard, Advanced) and PHP version >= 8.1, and starting from April 22nd for all GLPI Cloud instances.

This plugin adds the ability to summarize the timeline items of tickets using the Open AI API. 

Find the documentation here: https://services.glpi-network.com/documentation/1864/file/README.md

View our brochure to find out more : https://glpi-project.org/wp-content/uploads/EN.pdf

GLPI AI is building on OpenAI

GLPI Agent: Release 1.7.3

GLPI Agent 1.7.3 has been released.

You can download it on the GLPI Agent github project: https://github.com/glpi-project/glpi-agent/releases/tag/1.7.3

This version essentially fixes a regression introduced in the MSI packaging for Windows in the 1.7.2 version:

  • the LOCAL parameter was forced to the agent installation folder when not used. After that, local inventory was also generated even if this wasn’t required. This LOCAL configuration will be removed during this update.
  • CVE-2024-28241 patch was modified to not be enabled if the installation folder and (if used) the LOCAL parameter remain under the default system folder as there’s not security issue in that case.

These updates only impact Windows installation performed with MSI packaging.

We invite you to upgrade your agents on Windows as soon as possible.

You don’t need to upgrade to 1.7.3 GLPI Agents that were not installed on Windows and which are at least in 1.7 version.

Stay connected! Follow us on our social media platforms!

GLPI Agent 1.7.2 available!

GLPI Agent 1.7.2 has been released!

GLPI Agent Release 1.7.2

You can download it on the GLPI Agent github project: https://github.com/glpi-project/glpi-agent/releases/tag/1.7.2

This version specifically fixes 2 critical security issues related to MSI packaging on windows:

  • CVE-2024-28240: A local user could modify the GLPI Agent configuration to gain higher privileges.
  • CVE-2024-28241: A local user could modify the GLPI-Agent installation to gain higher privileges, but only when GLPI Agent is not installed in the default installation folder.

These security issues impact all Windows installation performed with MSI packaging.

We encourage you to upgrade all these agents as soon as possible!

Anyway you don’t need to upgrade to 1.7.2 after updating to 1.7.1 if your GLPI Agent was not installed on windows with the MSI package.

New silver Partner in Colombia: Systesol SAS

Congratulations ! We are happy to announce our new Silver GLPI Network partner in Colombia: Systesol SAS.

SYSTESOL – SYSTEMS & TECHNOLOGY SOLUTIONS SAS, is a company that integrates technological services and solutions; We offer solutions that adapt to the needs of our clients. Supply, administration and configuration of technological infrastructure.

Website: https://bit.ly/3TCVsSk

We are excited that GLPI ITSM solution is becoming more and more represented all over the world and GLPI Network (our support offer for on-premises – get your IT Infrastructure secured) subscription service will be available for more customers through our new partners.

Our large partnership network is always open for new collaborations. If you are interested in representing one of our products in your country, get in touch with us: https://glpi-project.org/contact_us/

Being a partner means:

  • Having an a direct access to the Teclib´s tech expertise;
  • Get special discounts;
  • Access official support,
  • Many other tools which will help you to gain more customers and increase reputation on the market by adding open source ITSM to your portfolio.

Discover all benefits of being a partner here: https://glpi-project.org/partners/

GLPI Release 10.0.14

A new GLPI version is available.

Due to a few regressions in the last (10.0.13), an early release is available.

You can download the GLPI 10.0.14 archive on GitHub.

Here is the list of corrections made in this version:

  • Fix assign field when suppliers assign is available
  • Switching entities issues

Regards.

GLPI Release 10.0.13

A new GLPI version is available!

This release fixes a few security issues that have been recently discovered. Update is recommended!

You can download the GLPI 10.0.13 archive on GitHub.

You will find below the list of security issues fixed in this bugfixes version:

  • SQL Injection in through the search engine (CVE-2024-27096)
  • Blind SSRF using Arbitrary Object Instantiation (CVE-2024-27098)
  • Stored XSS in dashboards (CVE-2024-27104)
  • Reflected XSS in debug mode (CVE-2024-27914)
  • Sensitive fields access through dropdowns (CVE-2024-27930)
  • Users emails enumeration (CVE-2024-27937)

Also, here is a short list of main changes done in this version:

  • Error when creating a Ticket with SLA/OLA.
  • Weekly recurrent reservations creation does not work.

The full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.