Permalink
CVE-2025-24022
8.6 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
iTop server vulnerable to portal code injection
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
References
-
https://github.com/Combodo/iTop/security/advisories/GHSA-rhv2-wfrr-4j2j x_refsource_CONFIRM
Affected products
iTop
- ==>= 3.2.0, < 3.2.1
- ==< 2.7.12
- ==>= 3.0.0, < 3.1.3
Matching in nixpkgs
pkgs.nvitop
Interactive NVIDIA-GPU process viewer, the one-stop solution for GPU process management
pkgs.psitop
Top for /proc/pressure
pkgs.gitopper
Gitops for non-Kubernetes folks
pkgs.weave-gitops
Weave Gitops CLI
pkgs.luaPackages.luabitop
Lua Bit Operations Module
pkgs.lua51Packages.luabitop
Lua Bit Operations Module
pkgs.luajitPackages.luabitop
Lua Bit Operations Module
pkgs.tailscale-gitops-pusher
Allows users to use a GitOps flow for managing Tailscale ACLs
pkgs.python312Packages.anitopy
Python library for parsing anime video filenames
Package maintainers
-
@luftmensch-luftmensch Valentino Bocchetti <valentinobocchetti59@gmail.com>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@figsoda figsoda <figsoda@pm.me>
-
@PassiveLemon PassiveLemon <jeremyseber@gmail.com>
-
@snue Stefan Nuernberger <kabelfrickler@gmail.com>
-
@blitz Julian Stecklina <js@alien8.de>
-
@xanderio Alexander Sieg <alex@xanderio.de>