PT-2020-9401 · Otrs+1 · Otrs+1
Tobias Kirchner
·
Published
2020-03-10
·
Updated
2023-01-27
·
CVE-2019-13457
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8
Description:
An issue was discovered in Open Ticket Request System (OTRS) where a customer user can use the search results to disclose information from their "company" tickets, even when the CustomerDisableCompanyTicketAccess setting is turned on. This allows access to tickets with the same CustomerID.
Recommendations:
For versions 7.0.x through 7.0.8, consider disabling the search function for customer users until a patch is available, or adjust the CustomerDisableCompanyTicketAccess setting to restrict access to company tickets.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs
Suse