CVE-2020-1777: Agent names disclosed in chat feature
Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside the tickets, when system is configured to mask real agent names. This issue affects OTRS; 7.0.21 and prior versions, 8.0.6 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-1777?
CVE-2020-1777 is a vulnerability in OTRS that reveals agent names in certain parts of the external interface and chat transcriptions inside tickets.
How does CVE-2020-1777 affect OTRS?
CVE-2020-1777 affects OTRS versions 7.0.21 and prior, as well as 8.0.6 and prior.
What is the severity of CVE-2020-1777?
The severity of CVE-2020-1777 is medium, with a CVSS score of 5.3.
How can I fix CVE-2020-1777?
To fix CVE-2020-1777, update OTRS to version 7.0.22 or 8.0.7, or later.
Where can I find more information about CVE-2020-1777?
You can find more information about CVE-2020-1777 in the OTRS Security Advisory 2020-15: [OTRS Security Advisory 2020-15](https://otrs.com/release-notes/otrs-security-advisory-2020-15/)