MEDIUM
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19
Published Aug 21, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.81%
Description
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html vendor-advisoryBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html vendor-advisoryBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html vendor-advisoryBroken Link
- https://community.otrs.com/security-advisory-2019-10-security-update-for-otrs-framework/ PatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4334 Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00018.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html mailing-list
- https://www.otrs.com/category/release-and-security-notes-en/ Release Notes
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | vendor-advisoryBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | vendor-advisoryBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | vendor-advisoryBroken Link | |
| https://community.otrs.com/security-advisory-2019-10-security-update-for-otrs-framework/ | PatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4334 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/08/msg00018.html | Mailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing-list | |
| https://www.otrs.com/category/release-and-security-notes-en/ | Release Notes |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 21, 2019
Updated Aug 4, 2024
Reserved Jun 6, 2019
Link CVE-2019-12746
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-4334 Assigner mitre
Published Aug 21, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-4334