Session / Password / Password token leak
Published Mar 27, 2020
8.1
HIGHCVSS 3.1
EPSS 1.46%
Description
An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.
Affected products
-
- Version 7.0.15 and priorStatusaffectedConstraints-
- Version
-
- Version 5.0.41 and priorStatusaffectedConstraints-
- Version 6.0.26 and priorStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to OTRS 7.0.16, ((OTRS)) Community Edition 6.0.27, 5.0.42
Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/ab253734bc211541309b9f8ea2b8b70389c4a64e Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/4955521af50238046847bce51ad9865950324f77
References (6)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html vendor-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12599 Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html mailing-list
- https://otrs.com/release-notes/otrs-security-advisory-2020-10/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | vendor-advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | vendor-advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | vendor-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12599 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing-list | |
| https://otrs.com/release-notes/otrs-security-advisory-2020-10/ | Vendor Advisory |
Change history (0)
No recorded changes yet.