CVE-2021-41245: Possible Cross-Site Request Forgery in Combodo iTop
Published Apr 5, 2022
·Updated
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by privUITransactionFile aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.
Affected Software
1 affected component
iTop<2.7.6
Remediation
Event History
Apr 5, 2022
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41245.
2
What is the severity of CVE-2021-41245?
The severity of CVE-2021-41245 is high with a severity value of 8.1.
3
What is the affected software for CVE-2021-41245?
The affected software for CVE-2021-41245 is Combodo iTop prior to version 2.7.6 and 3.0.0.
4
How can I fix CVE-2021-41245?
To fix CVE-2021-41245, update to version 2.7.6 or 3.0.0 of Combodo iTop.
5
Is there a workaround for CVE-2021-41245?
As a workaround for CVE-2021-41245, you can use the session implementation by adding it to the iTop configuration.