CVE-2021-21406: Command Injection vulnerability in the Setup Wizard
Published Jul 21, 2021
·Updated
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.
Affected Software
3 affected components
iTop<2.7.4
iTop=2.7.5
iTop=2.7.5-1
Event History
Jul 21, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21406?
CVE-2021-21406 is classified as a high severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2021-21406?
To fix CVE-2021-21406, upgrade to Combodo iTop version 2.7.4 or later.
3
What causes CVE-2021-21406?
CVE-2021-21406 is caused by improper validation of the Graphviz executable path in the Setup Wizard.
4
Which versions of Combodo iTop are affected by CVE-2021-21406?
CVE-2021-21406 affects Combodo iTop versions prior to 2.7.4.
5
Is CVE-2021-21406 publicly known?
Yes, CVE-2021-21406 is publicly disclosed and documented in security advisories.