Back

HIGH

Session / Password / Password token leak

Published Mar 27, 2020

Description

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

Affected products

Remediation

Vendor solution

Upgrade to OTRS 7.0.16, ((OTRS)) Community Edition 6.0.27, 5.0.42

Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/ab253734bc211541309b9f8ea2b8b70389c4a64e Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/4955521af50238046847bce51ad9865950324f77

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OTRS
Published Mar 27, 2020
Updated Sep 16, 2024
Reserved Nov 29, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner OTRS
Published Mar 27, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2020-12599