PT-2025-1321 · Otrs · Otrs

Alissa Kim

·

Published

2025-01-21

·

Updated

2025-01-27

·

CVE-2025-24390

CVSS v4.0

7.4

High

VectorAV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/R:A/RE:L/U:Clear
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 8.0.X OTRS versions 2023.X through 2024.X
Description The issue is related to a vulnerability in the OTRS Application Server and reverse proxy settings, which allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This can enable a remote attacker to hijack sessions.
Recommendations For OTRS versions 7.0.X, update the reverse proxy settings to include the necessary attributes for sensitive cookie settings. For OTRS versions 8.0.X, ensure that the HTTPS sessions have the correct attributes set for sensitive cookies. For OTRS versions 2023.X and 2024.X, apply the recommended configuration changes to the reverse proxy settings to mitigate the issue. As a temporary workaround, consider restricting access to sensitive areas of the application until the issue is fully resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01036
CVE-2025-24390

Affected Products

Otrs