PT-2019-13346 · Otrs+2 · Otrs+2

CVE-2019-13458

·

Publicado

2019-08-12

·

Atualizado

2023-08-31

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8 Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19
Description An issue was discovered that allows an attacker who is logged into OTRS as an agent user with appropriate permissions to disclose hashed user passwords by leveraging OTRS notification tags in templates.
Recommendations For OTRS versions 7.0.x through 7.0.8, update to a version that contains a fix for this issue. For OTRS Community Edition versions 5.0.x through 5.0.36, update to a version that contains a fix for this issue. For OTRS Community Edition versions 6.0.x through 6.0.19, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to OTRS notification tags in templates to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2019-3068
ALT-PU-2019-3183
CVE-2019-13458
DLA-1877-1
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Produtos afetados

Alt Linux
Otrs
Suse