First published: Wed Aug 21 2019(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=5.0.0<=5.0.36 | |
OTRS | >=6.0.0<=6.0.19 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12746 is classified as a medium severity vulnerability.
To fix CVE-2019-12746, upgrade to OTRS Community Edition version 5.0.37 or 6.0.20 or later.
CVE-2019-12746 affects OTRS Community Edition versions 5.0.x through 5.0.36 and 6.0.x through 6.0.19.
CVE-2019-12746 exploits a vulnerability where a session ID can be disclosed by sharing links of embedded ticket articles.
CVE-2019-12746 impacts systems running affected versions of OTRS Community Edition and potentially Debian Linux 8.0.