CVE-2010-4768: Medium severity OTRS OTRS vulnerability
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4768?
CVE-2010-4768 has a severity rating of medium, as it allows remote authenticated users to bypass queue access restrictions.
How do I fix CVE-2010-4768?
To fix CVE-2010-4768, upgrade to OTRS version 2.3.5 or later, where the issue is resolved.
Which versions are affected by CVE-2010-4768?
CVE-2010-4768 affects OTRS versions before 2.3.5, including numerous beta and release candidate versions.
What are the potential risks of CVE-2010-4768?
The risks associated with CVE-2010-4768 include unauthorized access and manipulation of tickets by users who should not have permissions.
Is there a patch available for CVE-2010-4768?
There is no specific patch for CVE-2010-4768; upgrading to the fixed version is the recommended solution.