CVE-2018-20800: Input Validation
Published Mar 13, 2019
·Updated
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.
Affected Software
2 affected components
OTRS OTRS=5.0.31
OTRS OTRS=6.0.13
Remediation
Event History
Mar 13, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20800?
CVE-2018-20800 has been assigned a high severity due to the potential for data loss during updates.
2
How do I fix CVE-2018-20800?
To mitigate CVE-2018-20800, avoid updating to versions 5.0.31 or 6.0.13 without ensuring backups are in place.
3
What versions of OTRS are affected by CVE-2018-20800?
CVE-2018-20800 affects OTRS versions 5.0.31 and 6.0.13.
4
What type of data is lost due to CVE-2018-20800?
CVE-2018-20800 specifically leads to data loss in the agent preferences table.
5
Is there a workaround for CVE-2018-20800?
Currently, the best practice for CVE-2018-20800 is to back up your data before performing any updates to affected versions.