PT-2024-34874 · Comodo+1 · Itop+1

Worty-Syn

·

Published

2024-11-05

·

Updated

2025-04-28

·

CVE-2024-51739

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.11 Combodo iTop versions prior to 3.0.5 Combodo iTop versions prior to 3.1.2 Combodo iTop versions prior to 3.2.0
Description The issue allows an unauthenticated user to perform user enumeration, making it easier to brute force a valid account. This is due to the sentence displayed after resetting a password indicating whether the user exists or not.
Recommendations For versions prior to 2.7.11, upgrade to version 2.7.11 or later. For versions prior to 3.0.5, upgrade to version 3.0.5 or later. For versions prior to 3.1.2, upgrade to version 3.1.2 or later. For versions prior to 3.2.0, upgrade to version 3.2.0 or later. As a temporary workaround for users unable to upgrade, overload the dictionary entry UI:ResetPwd-Error-WrongLogin through an extension and replace it with a generic message.

Exploit

Fix

Information Disclosure

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2025-4212
CVE-2024-51739
GHSA-2HMF-P27W-PHF9

Affected Products

Alt Linux
Itop