Vulnerability Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | < 2.7.8 |
Related Weaknesses (CWE)
References
- https://github.com/Combodo/iTop/commit/4c1df9927d1dc6b0181ee20721f93346def026fdPatch
- https://github.com/Combodo/iTop/commit/bdebea62b642622ed71410b26c81e8537e6e58faPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-vj96-j84g-jhx4Vendor Advisory
- https://github.com/Combodo/iTop/commit/4c1df9927d1dc6b0181ee20721f93346def026fdPatch
- https://github.com/Combodo/iTop/commit/bdebea62b642622ed71410b26c81e8537e6e58faPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-vj96-j84g-jhx4Vendor Advisory
FAQ
What is CVE-2022-39214?
CVE-2022-39214 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the accoun...
How severe is CVE-2022-39214?
CVE-2022-39214 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-39214?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.