Skip to content

web.config files lack to protect certain directories

Critical
piRGoif published GHSA-97cw-cjxc-9x78 Sep 18, 2020

Package

No package listed

Affected versions

<2.7.1, < 3.0.0

Patched versions

2.7.1, 3.0.0

Description

Impact

When using iTop on IIS, on affected version the embedded web.config files are not protecting all the directories that should be forbidden from web access.

Patches

  • 2.7.1 : packages community, essential, professional
  • 3.0.0 : to be published

Credits

Many thanks to TW/CERT for his report !

References

Combodo ref N°2984
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12780
https://www.itophub.io/wiki/page?id=latest%3Ainstall%3Asecurity#secure_critical_directories_access

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

Critical

CVE ID

CVE-2020-12780

Weaknesses

No CWEs