CVE-2024-52001: Portal user is able to access forbidden services information in Combodo iTop
Published Nov 8, 2024
·Updated
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
1 affected component
iTop<3.2.0
Event History
Nov 8, 2024
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52001?
CVE-2024-52001 is considered a medium severity vulnerability due to improper access control allowing unauthorized information exposure.
2
How do I fix CVE-2024-52001?
To fix CVE-2024-52001, users must upgrade to version 3.2.0 of Combodo iTop.
3
What specific information can be accessed due to CVE-2024-52001?
CVE-2024-52001 allows portal users to access forbidden services information that should be restricted.
4
Are there any known workarounds for CVE-2024-52001?
There are no known workarounds for CVE-2024-52001, so upgrading is essential.
5
Which versions of Combodo iTop are affected by CVE-2024-52001?
All versions of Combodo iTop prior to 3.2.0 are affected by CVE-2024-52001.