PT-2020-15053 · Otrs+1 · Otrs+2

Marvin Voormann

·

Published

2020-07-20

·

Updated

2023-08-31

·

CVE-2020-1776

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTRS Community Edition versions 6.0.28 and prior OTRS versions 7.0.18 and prior OTRS versions 8.0.4 and prior
Description The issue occurs when an agent user is renamed or set to invalid, and the session belonging to the user remains active. Although the session cannot be used to access ticket data if the agent is invalid, it still poses a problem.
Recommendations For OTRS Community Edition versions 6.0.28 and prior, update to a version later than 6.0.28. For OTRS versions 7.0.18 and prior, update to a version later than 7.0.18. For OTRS versions 8.0.4 and prior, update to a version later than 8.0.4.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2649
ALT-PU-2020-2748
CVE-2020-1776
DLA-3551-1

Affected Products

Alt Linux
Otrs
Otrs Community Edition