New GLPI version 10.0.4

A new GLPI version is available.

This release fixes several security issues that has been recently discovered. Update is recommended!

You can download the GLPI 10.0.4 archive on GitHub.
We also provide a security release for 9.5 branch : GLPI 9.5.10 archive

You will find below the list of security issues fixed in this bugfixes version:

  • Blind SSRF in RSS feeds and planning (CVE-2022-39276)
  • Stored XSS in user information (CVE-2022-39372)
  • Stored XSS in entity name (CVE-2022-39373)
  • Improper input validation on emails links (CVE-2022-39376)
  • Improper access to debug panel (CVE-2022-39370)
  • User’s session persist after permanently deleting his account (CVE-2022-39234)
  • Stored XSS on login page (CVE-2022-39262)
  • XSS in external links (CVE-2022-39277)
  • XSS through public RSS feed (CVE-2022-39375)
  • SQL Injection on REST API (CVE-2022-39323)
  • Stored XSS through asset inventory (CVE-2022-39371)

Also, here is a short list of main changes done in this version:

  • Increase significantly dashboards performance
  • Several bugs on images pasting
  • Fixed and improved inventory locks management
  • Display of printer cartridges
  • Display and hide actors tooltips in tickets
  • Improve display of headers above forms
  • Move breakpoints on responsive displays
  • Inventory API is now disabled by default
  • Dedicated rights has been added for inventory

The full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.

Success story: Neocos Laboratories

We met with Alejandro Rodríguez Girbés, who leads the IT department of the company Neocos Laboratorios, located in Valencia, Spain.

The company manufactures hair dyes and hair care products for companies such as Mercadona. In this interview you will discover what GLPI tools Alejandro uses in his day to day life and how he improves his work and that of his team.

Interview:

– Hi Alejandro, thank you very much for joining us today. Please could you tell us your name and position

– My name is Alejandro Rodriguez, I work in Neocos Laboratorios as IT responsible for the IT of the company. We are dedicated to make hair dyes for Mercadona, I have more than 100 users, about 150.

-How did you hear about GLPI? What was the first version you tried?

– I have been using GLPI for maybe 5 years now. We implemented it in the company and it is a tool that being free is very easy to introduce to management and learn how to use it and then as soon as the users see how easy it is to put tickets it is very easy to implement in the company.


– How did you find out about GLPI?

I don’t remember how I found out about it. I think I was searching the internet looking for tools that would allow me to implement ITIL standards and one day I came across GLPI and since that day I have implemented it in this and other companies I have been in.


-What version are you currently using?
– I am currently starting to use the latest version 10.0.3 since the last two weeks. And my idea, is, once I finish implementing it well, to go to the Cloud version for convenience.


– What GLPI functions do you use? Helpdesk, Asset Management, Problem Management, Change Management, Financial Management, Reporting, User Management, Knowledge Base, etc.?
– I have always used it for inventorying all my IT equipment and for ticketing but then the ticketing part also has associated internal management of recurring cases and so on and in this version 10, which is already integrated the issue of inventorying more comfortable, in fact the documentation I found it right away and I inventoried all my part.
Now with this version 10 I am also inventorying the terminals that before I did not do it and now it is very simple and I am even with the management of contracts, budgets and projects. I think I use everything or almost everything! It is very comfortable for me!


– Do you use any GLPI network plugins? If yes, which ones?
– Not at the moment. I did install the IPs plugin and so on, but I didn’t have time.


– How does GLPI help you in your work? What were your requirements for the software and what business/IT problems were you willing to solve with GLPI?
– Starting with ticketing, it is very convenient for me to keep a record of the day to day quantified in numbers, then, it is very useful to keep the inventory of all the park I have, in that sense it is very comfortable because I can draw statistics and then take action based on that, and keep a budget item for the issue of hardware, software. Likewise, it is easier to keep a record of each year’s investment than to look at it folder by folder.


– What is the best feature of GLPI for you?
– Of the whole package, the best is the inventory, having integrated it natively into the tool. For me it has been a very attractive solution.


– Can you give an overall assessment of GLPI (summarize your experience with GLPI)?
– The ease of implementation and the ease of starting to use it. If I have a need, I just look where it is and that’s it. For example, with the issue of recording internal invoicing, it is very convenient for me, the issue of getting a report on the age of the hardware, it is very easy to work with the tool.

– Great, very good. Thank you very much for all your answers, very clear.

New Silver Partner: HarPer Srl

We are happy to announce our new silver partner in the Dominican Republic – HarPer Srl.

HarPer Srl is an IT company primarily engaged in providing cybersecurity technological solutions to their customers.

They provide support of businesses throughout their life cycles from installment of new infrastructure, development of new systems, secure their data or even their physical locations. Also, they provide guidance or recommendations for business continuity.

Among many solutions, HarPer Srl offers:

  • Pentesting, hardening access control, vulnerability Assessment, implementation of information security improvements.
  • Implementation and troubleshooting of networks and infrastructure.
  • Development of desktop, web and mobile applications.
  • IT, network and security trainings|Project Management, Agile (Scrum, Kanban, etc.).

Website: https://www.har-per.com/

We are excited that GLPI ITSM solution is becoming more and more represented all over the world and GLPI Network (our support offer for on-premises – get your IT Infrastructure secured) subscription service will be available for more customers through our new partners.

Our large partnership network is always open for new collaborations. If you are interested in representing one of our products in your country, get in touch with us: https://glpi-project.org/contact/

Being a partner means:

  • Having an a direct access to the Teclib´s tech expertise;
  • Get special discounts;
  • Access official support,
  • Many other tools which will help you to gain more customers and increase reputation on the market by adding open source ITSM to your portfolio.

Discover all benefits of being a partner here: https://glpi-project.org/partners/

New GLPI version 10.0.3

A new GLPI version is available.

This release fixes several critical security issues that has been recently discovered. Update is strongly recommended!

You can download the GLPI 10.0.3 archive on GitHub.
Exceptionally, as we have critical security issues that affects GLPI 9.5, we also release a GLPI 9.5.9 archive.

You’ll find below the list of security issues fixed in this bugfixes version:

  • XSS through registration API (CVE-2022-35945)
  • Leak of sensitive information through login page error (CVE-2022-31143)
  • Stored XSS through global search (CVE-2022-31187)
  • Command injection using a third-party library script (CVE-2022-35914)
  • SQL injection through plugin controller (CVE-2022-35946)
  • Authentication via SQL injection (CVE-2022-35947)
  • Blind Server-Side Request Forgery (SSRF) in RSS feeds and planning (CVE-2022-36112)

Also, here is a short list of main changes done in this version:

  • More precise rights checks on inventory (#12610)
  • Display of last inventoried value for locked fields (#12602)
  • Permit to use rules to add computers as virtual machines (#12572)
  • Delegate session cookies security to sysadmin (#12302)
  • Prevent collector failure on invalid mail header (#12232)
  • Many fixes on network inventory

The full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.

New silver partner : ANC Technology Services S.A (Amvix)

We are happy to announce our new silver partner in Costa Rica – ANC Technology Services S.A (Amvix).

ANC Technology Services S.A (Amvix) is a company with more than 14 years of experience in the market. They are specialized in OpenSource technologies for the implementation of network, security, Internet and CRM solutions.

They provide support in preventive management, consulting and infrastructure scaling. They approach the business opportunities offered by new computing technologies.

Among many solutions, ANC Technology Services S.A (Amvix) offers:

  • Consulting and Advisory.
  • Installation and configuration of Linux servers.
  • Desktop and application virtualization.
  • Technical support.

Websitehttp://www.amvix.com/

We are excited that GLPI ITSM solution is becoming more and more represented all over the world and GLPI Network (our support offer for on-premises – get your IT Infrastructure secured) subscription service will be available for more customers through our new partners.

Our large partnership network is always open for new collaborations. If you are interested in representing one of our products in your country, get in touch with us: https://glpi-project.org/contact/

Being a partner means:

  • Having an a direct access to the Teclib´s tech expertise;
  • Get special discounts;
  • Access official support,
  • Many other tools which will help you to gain more customers and increase reputation on the market by adding open source ITSM to your portfolio.

Discover all benefits of being a partner here: https://glpi-project.org/partners/