CVE-2020-1768: External Interface does not invalidate session
Published Feb 7, 2020
·Updated
The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
Affected Software
1 affected component
OTRS OTRS>=7.0.0<=7.0.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 7.0.15
Event History
Feb 7, 2020
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-1768?
CVE-2020-1768 is rated as a medium severity vulnerability.
2
How do I fix CVE-2020-1768?
To fix CVE-2020-1768, upgrade OTRS to version 7.0.15 or later.
3
What software is affected by CVE-2020-1768?
CVE-2020-1768 affects OTRS versions 7.0.14 and earlier.
4
What is the impact of CVE-2020-1768?
CVE-2020-1768 can prevent the SessionMaxIdleTime from being reached due to excessive background calls.
5
When was CVE-2020-1768 disclosed?
CVE-2020-1768 was disclosed in April 2020.