In iTop versions before 3.2.0 a high severity vulnerability CVE-2024-52000 was detected. It allows attackers to run malicious JavaScript by modifying request payloads. This issue is fixed in version 3.2.0 through improved error message handling. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52000.
Read more IT Business ManagementIn iTop versions prior to 2.7.11, from 3.0.0 up to 3.0.5, and from 3.1.0 up to 3.1.2 a medium severity vulnerability CVE-2024-49367 was found. This vulnerability allows low-privileged users create HTTP requests as the server. The issue was fixed by limiting access in the user portal to only safe functions. To address this issue, upgrade to versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-49367.
Read more IT Business ManagementIn Foreman version 3.9.0 a medium severity vulnerability CVE-2024-8553 was detected. This vulnerability allows attackers to exploit loader macros to bypass access controls and read any database field if they have permission to create or view report templates. To fix this issue, users should update Foreman to version 3.9.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8553.
Read more IT Business ManagementIn Ansible version 2 a medium severity vulnerability CVE-2024-10033 was detected. This vulnerability allows attackers to inject malicious scripts, redirect users, or steal sessions and data by exploiting the “?next=” parameter in a URL. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-10033.
Read more IT Business ManagementIn Foreman versions 6.13, 6.14 and 6.15 a critical severity vulnerability CVE-2024-7012 was detected. This vulnerability allows unauthorized users to gain admin access due to improper header handling by Apache’s mod_proxy. To fix this problem, users should upgrade to versions 6.13.7.2, 6.14.4.2, or 6.15.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7012.
Read more IT Business ManagementIn Foreman versions before 3.11.1 a medium severity vulnerability CVE-2024-7700 was detected. This vulnerability allows attackers to exploit user actions to execute malicious code. To fix this issue, users should upgrade Foreman to version 3.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7700.
Read more IT Business ManagementIn iTop a high severity vulnerability CVE-2023-47622 was detected. Refreshing dashlets could allow attackers to inject harmful code into the webpage if the system doesn’t properly clean up user-entered data. The issue is resolved in versions 3.0.4 and 3.1.1. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-47622/.
Read more IT Business ManagementIn iTop a high severity vulnerability CVE-2023-48709 was detected. Users need to be careful when opening CSV or Excel files from the back office or portal as they may contain dangerous formulas that can lead to malicious code being executed on your computer, especially in Excel 2016. The issue is resolved in iTop 2.7.9, 3.0.4, 3.1.1, and 3.2.0 versions. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-48709/.
Read more IT Business ManagementIn iTop a critical severity vulnerability CVE-2023-48710 was detected. Due to this vulnerability files from the env-production folder, which should be restricted, were accessible, potentially exposing sensitive data from third-party modules. To address this issue, users should update iTop to versions 2.7.10, 3.0.4, 3.1.1 and 3.2.0. For more information, visit https://avd.aquasec.com/nvd/2023/cve-2023-48710/.
Read more IT Business Management