8.7

CVE-2021-32663

Unauthorized setup leads to SSRF in Combodo/iTop

iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CombodoItop SwEdition- Version < 2.6.5
CombodoItop SwEdition- Version >= 2.7.0 < 2.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.41% 0.692
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
security-advisories@github.com 8.7 2.2 5.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://github.com/Combodo/iTop/commit/43daa2ef088bf928a2386fa19324628c3f19b807
Patch
Third Party Advisory
https://github.com/Combodo/iTop/commit/6be9a87c150978752bc68baae1a5c4833ddadfec
Patch
Third Party Advisory
https://github.com/Combodo/iTop/security/advisories/GHSA-ghqc-r8f6-q9m9
Third Party Advisory