Credentials management in Debian Linux - CVE-2019-13458

 

Credentials management in Debian Linux - CVE-2019-13458

Published: August 21, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35603
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13458
CWE-ID: CWE-255
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.


Affected software

Debian Linux
otrs (Alpine package)

How to mitigate CVE-2019-13458

Install update from vendor's website.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins