#VU51869 Information disclosure in OTRS - CVE-2020-1772
Published: March 27, 2020 / Updated: April 1, 2021
OTRS
otrs.org
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
Remediation
External links
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html
- https://lists.debian.org/debian-lts-announce/2020/05/msg00000.html
- https://otrs.com/release-notes/otrs-security-advisory-2020-09/