CVE-2020-1775: Information disclosure in external interface
Published Jun 8, 2020
·Updated
BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0.3 and prior versions, 7.0.17 and prior versions.
Affected Software
2 affected components
OTRS OTRS>=7.0.0<7.0.18
OTRS OTRS>=8.0.0<8.0.3
Remediation
Information
Upgrade to OTRS 7.0.18 and OTRS 8.0.4.
Event History
Jun 8, 2020
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-1775?
CVE-2020-1775 is a vulnerability in OTRS that allows BCC recipients in mails sent from OTRS to be visible in the article detail on the external interface.
2
Which versions of OTRS are affected by CVE-2020-1775?
OTRS versions 8.0.3 and prior, as well as 7.0.17 and prior, are affected by CVE-2020-1775.
3
What is the severity of CVE-2020-1775?
CVE-2020-1775 has a severity level of medium, with a CVSS score of 4.3.
4
How can I fix CVE-2020-1775?
To fix CVE-2020-1775, you should update OTRS to version 8.0.3 or later, or version 7.0.18 or later.
5
Where can I find more information about CVE-2020-1775?
You can find more information about CVE-2020-1775 in the OTRS security advisory at https://otrs.com/release-notes/otrs-security-advisory-2020-12/