An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
References
Link | Resource |
---|---|
https://www.otrs.com/category/release-and-security-notes-en/ | Release Notes |
https://community.otrs.com/security-advisory-2019-12-security-update-for-otrs-framework/ | Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/08/msg00018.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | Broken Link |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | Broken Link |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | Broken Link |
Information
Published : 2019-08-21 07:15
Updated : 2023-01-20 08:26
NVD link : CVE-2019-13458
Mitre link : CVE-2019-13458
JSON object : View
CWE
Products Affected
debian
- debian_linux
otrs
- otrs