CVE-2019-18179: Medium severity otrs vulnerability
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18179?
CVE-2019-18179 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2019-18179?
To fix CVE-2019-18179, upgrade OTRS to version 7.0.13 or later for 7.0.x, version 6.0.24 or later for 6.0.x, or version 5.0.39 or later for 5.0.x.
Who is affected by CVE-2019-18179?
CVE-2019-18179 affects OTRS versions 7.0.x through 7.0.12, 6.0.x through 6.0.23, and 5.0.x through 5.0.38.
What kind of attack does CVE-2019-18179 enable?
CVE-2019-18179 enables an attacker, who is logged in as an agent, to view tickets assigned to other agents across different queues.
Is CVE-2019-18179 present in community editions of OTRS?
Yes, CVE-2019-18179 affects both the standard and community editions of OTRS within the specified version ranges.