RULE(RULE ID:338982)

Rule General Information
Release Date: 2025-05-28
Rule Name: Combodo iTop Hub Connector Information Disclosure Vulnerability (CVE-2024-32870)
Severity:
CVE ID:
Rule Protection Details
Description: Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://github.com/Combodo/iTop/security/advisories/GHSA-rfjh-2f5x-qxmx
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/Combodo/iTop/security/advisories/GHSA-rfjh-2f5x-qxmx