First published: Fri Feb 07 2020(Updated: )
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | >=7.0.0<=7.0.14 |
Upgrade to OTRS 7.0.15
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1768 is rated as a medium severity vulnerability.
To fix CVE-2020-1768, upgrade OTRS to version 7.0.15 or later.
CVE-2020-1768 affects OTRS versions 7.0.14 and earlier.
CVE-2020-1768 can prevent the SessionMaxIdleTime from being reached due to excessive background calls.
CVE-2020-1768 was disclosed in April 2020.