Back

HIGH

Information Disclosure

Published Mar 27, 2020

Description

It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

Affected products

Remediation

Vendor solution

Upgrade to OTRS 7.0.16, ((OTRS)) Community Edition 6.0.27, 5.0.42

Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/c0255365d5c455272b2b9e7bb1f6c96c3fce441b Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/96cc7826d6ce260204ff629fc968edd2787b7f6b

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner OTRS
Published Mar 27, 2020
Updated Sep 16, 2024
Reserved Nov 29, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner OTRS
Published Mar 27, 2020
Updated Sep 16, 2024

GitHub

No data