CVE-2020-15218: Admin pages are cached and can be embedded
Published Jan 13, 2021
·Updated
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.
Affected Software
2 affected components
iTop<2.7.2
iTop=3.0.0-alpha
Event History
Jan 13, 2021
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-15218?
CVE-2020-15218 has a medium severity rating due to the exposure of sensitive admin page contents after a user logs out.
2
How do I fix CVE-2020-15218?
To fix CVE-2020-15218, upgrade iTop to version 2.7.2 or later, or 3.0.0 if using the alpha version.
3
Which versions of iTop are affected by CVE-2020-15218?
CVE-2020-15218 affects iTop versions prior to 2.7.2 and 3.0.0-alpha.
4
What type of vulnerability is CVE-2020-15218?
CVE-2020-15218 is a caching vulnerability that exposes cached admin page content.
5
Can I mitigate the risks of CVE-2020-15218 without upgrading?
Mitigation options are limited without upgrading, but ensure users clear their browser cache after logging out.