PT-2021-14483 · Comodo+1 · Combodo Itop+1

Markus Wulftange

·

Published

2021-07-21

·

Updated

2024-04-04

·

CVE-2021-21406

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.4
Description The issue is related to a command injection vulnerability in the Setup Wizard of Combodo iTop when providing the Graphviz executable path.
Recommendations For versions prior to 2.7.4, update to version 2.7.4 or 3.0.0 to resolve the issue.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-21406
GHSA-PF95-6H7Q-Q85X

Affected Products

Alt Linux
Combodo Itop