CVE-2021-32775: Any user can see any fields (including mailbox password) with GroupBy Dashlet
Published Jul 21, 2021
·Updated
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
Affected Software
4 affected components
iTop<2.7.4
iTop=3.0.0-alpha
iTop=3.0.0-beta
iTop=3.0.0-beta2
Event History
Jul 21, 2021
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32775?
The severity of CVE-2021-32775 is high, with a severity value of 6.5.
2
How can a non-admin user exploit CVE-2021-32775?
A non-admin user can exploit CVE-2021-32775 by accessing class/field values through the GroupBy Dashlet error message.
3
Which versions of Combodo iTop are affected by CVE-2021-32775?
Versions prior to 2.7.4 are affected by CVE-2021-32775.
4
How can I fix CVE-2021-32775?
You can fix CVE-2021-32775 by updating to version 2.7.4 or 3.0.0 of Combodo iTop.
5
Are there any references to learn more about CVE-2021-32775?
Yes, you can find more information about CVE-2021-32775 at the following link: [GitHub Advisory](https://github.com/Combodo/iTop/security/advisories/GHSA-xh7w-rrp3-fhpq).