Impact
Redos that may, under some circumstances, affect iTop server.
Patches
Not using variable in regexp anymore since version 3.2.1
Workarounds
If iTop app_root_url is hard coded in the configuration file, then there is no possible way to exploit this redos.
References
- Combodo N°6284 - Redos in regex
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Impact
Redos that may, under some circumstances, affect iTop server.
Patches
Not using variable in regexp anymore since version 3.2.1
Workarounds
If iTop app_root_url is hard coded in the configuration file, then there is no possible way to exploit this redos.
References
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com