Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-03-18 09:55
Updated : 2011-03-21 21:00
NVD link : CVE-2010-4768
Mitre link : CVE-2010-4768
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
otrs
- otrs