An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | Broken Link |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | Broken Link |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | Broken Link |
https://community.otrs.com/security-advisory-2019-12-security-update-for-otrs-framework/ | Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/08/msg00018.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | |
https://www.otrs.com/category/release-and-security-notes-en/ | Release Notes |
Configurations
History
No history.
Information
Published : 2019-08-21 14:15
Updated : 2023-08-31 03:15
NVD link : CVE-2019-13458
Mitre link : CVE-2019-13458
CVE.ORG link : CVE-2019-13458
JSON object : View
Products Affected
debian
- debian_linux
otrs
- otrs
CWE