PT-2021-7217 · Comodo+1 · Itop+1

Published

2021-06-21

·

Updated

2024-04-04

·

CVE-2021-32776

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.4
Description The issue is related to the reuse of CSRF tokens by a malicious user, as no cleanup is done on these tokens on Windows servers. This can allow a remote attacker to perform a CSRF attack.
Recommendations For versions prior to 2.7.4, update to version 2.7.4 or 3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive operations that rely on CSRF tokens until a patch is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
BDU:2022-03877
CVE-2021-32776
GHSA-CXW7-2X7H-F7PR

Affected Products

Alt Linux
Itop