CVE-2025-24026

iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.
Configurations

No configuration.

History

16 May 2025, 14:43

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 15:15

Updated : 2025-05-16 14:43


NVD link : CVE-2025-24026

Mitre link : CVE-2025-24026

CVE.ORG link : CVE-2025-24026


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity