First published: Fri Nov 08 2024(Updated: )
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52001 is considered a medium severity vulnerability due to improper access control allowing unauthorized information exposure.
To fix CVE-2024-52001, users must upgrade to version 3.2.0 of Combodo iTop.
CVE-2024-52001 allows portal users to access forbidden services information that should be restricted.
There are no known workarounds for CVE-2024-52001, so upgrading is essential.
All versions of Combodo iTop prior to 3.2.0 are affected by CVE-2024-52001.