Vulnerability Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | < 2.7.8 |
Related Weaknesses (CWE)
References
- https://github.com/Combodo/iTop/commit/35a8b501c9e4e767ec4b36c2586f34d4ab66d229Patch
- https://github.com/Combodo/iTop/commit/f10e9c2d64d0304777660a4f70f1e80850ea864bPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-hggq-48p2-cmhmVendor Advisory
- https://github.com/Combodo/iTop/commit/35a8b501c9e4e767ec4b36c2586f34d4ab66d229Patch
- https://github.com/Combodo/iTop/commit/f10e9c2d64d0304777660a4f70f1e80850ea864bPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-hggq-48p2-cmhmVendor Advisory
FAQ
What is CVE-2022-39216?
CVE-2022-39216 is a vulnerability with a CVSS score of 7.4 (HIGH). Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to ...
How severe is CVE-2022-39216?
CVE-2022-39216 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39216?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.