CVE-2024-32870
iTop hub connector Information disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Combodo iTop es una herramienta de gestión de servicios de TI sencilla y basada en la web. Cualquier persona que tenga acceso a la URI de iTop puede leer la información del servidor, el sistema operativo, el DBMS, PHP e iTop (nombre, versión y parámetros). Este problema se ha corregido en las versiones 2.7.11, 3.0.5, 3.1.2 y 3.2.0. Se recomienda a los usuarios que actualicen la versión. No se conocen soluciones alternativas para esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-19 CVE Reserved
- 2024-11-04 CVE Published
- 2024-11-05 CVE Updated
- 2024-11-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/Combodo/iTop/security/advisories/GHSA-rfjh-2f5x-qxmx | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | < 2.7.11 Search vendor "Combodo" for product "ITop" and version " < 2.7.11" | en |
Affected
| ||||||
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | >= 3.0.0 < 3.0.5 Search vendor "Combodo" for product "ITop" and version " >= 3.0.0 < 3.0.5" | en |
Affected
| ||||||
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | >= 3.1.0 < 3.1.2 Search vendor "Combodo" for product "ITop" and version " >= 3.1.0 < 3.1.2" | en |
Affected
|