iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.
History

Wed, 14 May 2025 15:15:00 +0000

Type Values Removed Values Added
Description iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.
Title iTop Inefficient Regular Expression Complexity vulnerability
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-14T14:59:47.581Z

Updated: 2025-05-14T15:10:59.790Z

Reserved: 2025-01-16T17:31:06.460Z

Link: CVE-2025-24026

cve-icon Vulnrichment

Updated: 2025-05-14T15:10:55.832Z

cve-icon NVD

Status : Received

Published: 2025-05-14T15:15:56.440

Modified: 2025-05-14T15:15:56.440

Link: CVE-2025-24026

cve-icon Redhat

No data.