Information disclosure in Debian Linux - CVE-2019-12746

 

Information disclosure in Debian Linux - CVE-2019-12746

Published: August 21, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35602
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12746
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.


Affected software

Debian Linux
otrs (Alpine package)

How to mitigate CVE-2019-12746

Install update from vendor's website.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins