First published: Wed Apr 01 2020(Updated: )
An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Deskpro Deskpro | <2019.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11465 is a vulnerability in Deskpro before version 2019.8.0 that allows an attacker to control/install helpdesk applications and leak current applications' configurations.
CVE-2020-11465 has a severity rating of 8.8 (high).
Deskpro versions up to and excluding 2019.8.0 are affected by CVE-2020-11465.
To fix CVE-2020-11465, upgrade to Deskpro version 2019.8.0 or later.
You can find more information about CVE-2020-11465 in the following references: [Link 1](https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/), [Link 2](https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09), [Link 3](https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update).