Menu

Internal Path Disclosure Issue

6 days ago
6 days ago
  • Naveenkumar R

    Naveenkumar R - 6 days ago

    I discovered a potential Internal Path Disclosure vulnerability in iTop, where certain error messages reveal internal server paths. How can this information be concealed?

     
  • Vincent @ Combodo

    No, those messages only occurs during the Setup, which is the process to install iTop. Those pages are not accessible 99.99% of the time.
    This should be performed by a person who knows the server and its architecture, so it is not a disclosure for him.
    So we won't do anything about it.

     
    👍
    1
    • jf-cbd

      jf-cbd - 6 days ago

      Hello @naveen-steigen, thanks for your message. As Vincent said, this is something that happens when going on the setup page ; and the path displayed is a relative path, that is the same for every iTop.

       
  • Naveenkumar R

    Naveenkumar R - 6 days ago

    Hi @jf-cbd @cisou
    Thank you for your prompt reply.
    In addition to the setup page, the internal path is also visible on the backup page. Please refer to the attached image for your reference.

     
  • Naveenkumar R

    Naveenkumar R - 6 days ago

    Hi @jf-cbd @cisou
    Thank you for your prompt reply.
    In addition to the setup page, the internal path is also visible on the backup page. Please refer to the attached image for your reference.

     
  • Vincent @ Combodo

    If I am not mistaken, Backup pages are limited to iTop administrators, so I don't see a risk for them to be aware of the backups path

     
    • Naveenkumar R

      Naveenkumar R - 6 days ago

      Thanks for the clarification. Since the backup pages are only accessible to iTop administrators, the risk does seem low.
      Still, is there any way to hide or mask the internal backup path in the iTop window.

       

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.