Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Bernhard Lehr

#54378of 56,330
4.3Total CVSS
Vulnerabilities · 1
PT-2021-14508
4.3
2021-02-08
Otrs Ag · Otrs Ag Otrscisincustomerfrontend · CVE-2021-21436
**Name of the Vulnerable Software and Affected Versions** OTRS AG OTRSCIsInCustomerFrontend versions 7.0.14 and prior versions. **Description** The issue allows agents to see and link Config Items without the necessary permissions, which are defined in the General Catalog. **Recommendations** For OTRS AG OTRSCIsInCustomerFrontend versions 7.0.14 and prior versions, update to a version that includes the necessary permission checks to restrict access to Config Items. As a temporary workaround, consider restricting access to the General Catalog to minimize the risk of exploitation.