VulnerabilityModified
CVE-2021-21407
Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure.
MEDIUM 6.5EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- combodo/itop
- Source
- security-advisories@github.com
References
- https://github.com/Combodo/iTop/security/advisories/GHSA-9wq8-4qm9-3j6fThird Party Advisory
- https://github.com/Combodo/iTop/security/advisories/GHSA-9wq8-4qm9-3j6fThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.