PT-2019-13346 · Otrs+2 · Otrs+2
Published
2019-08-12
·
Updated
2023-08-31
·
CVE-2019-13458
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8
Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36
Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19
Description
An issue was discovered that allows an attacker who is logged into OTRS as an agent user with appropriate permissions to disclose hashed user passwords by leveraging OTRS notification tags in templates.
Recommendations
For OTRS versions 7.0.x through 7.0.8, update to a version that contains a fix for this issue.
For OTRS Community Edition versions 5.0.x through 5.0.36, update to a version that contains a fix for this issue.
For OTRS Community Edition versions 6.0.x through 6.0.19, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to OTRS notification tags in templates to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Otrs
Suse