PT-2025-1321 · Otrs · Otrs
Alissa Kim
·
Published
2025-01-21
·
Updated
2025-01-27
·
CVE-2025-24390
CVSS v4.0
7.4
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/R:A/RE:L/U:Clear |
Name of the Vulnerable Software and Affected Versions
OTRS versions 7.0.X through 8.0.X
OTRS versions 2023.X through 2024.X
Description
The issue is related to a vulnerability in the OTRS Application Server and reverse proxy settings, which allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This can enable a remote attacker to hijack sessions.
Recommendations
For OTRS versions 7.0.X, update the reverse proxy settings to include the necessary attributes for sensitive cookie settings.
For OTRS versions 8.0.X, ensure that the HTTPS sessions have the correct attributes set for sensitive cookies.
For OTRS versions 2023.X and 2024.X, apply the recommended configuration changes to the reverse proxy settings to mitigate the issue.
As a temporary workaround, consider restricting access to sensitive areas of the application until the issue is fully resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs