A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response-
This issue affects OTRS: from 8.0.X through 8.0.37.
References
Link | Resource |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2023-11/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-11-27 10:15
Updated : 2023-12-01 02:31
NVD link : CVE-2023-6254
Mitre link : CVE-2023-6254
CVE.ORG link : CVE-2023-6254
JSON object : View
Products Affected
otrs
- otrs
CWE
CWE-522
Insufficiently Protected Credentials