CVE-2020-1778: Bypassing user account validation
Published Nov 23, 2020
·Updated
When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
Affected Software
1 affected component
OTRS OTRS<=8.0.9
Remediation
Information
Upgrade to OTRS 8.0.10
Event History
Nov 23, 2020
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-1778.
2
What is the title of the vulnerability?
The title of the vulnerability is 'When OTRS uses multiple backends for user authentication (with LDAP) agents are able to login even if the account is set to invalid.'
3
What is the severity of CVE-2020-1778?
The severity of CVE-2020-1778 is medium with a severity value of 4.3.
4
Which versions of OTRS are affected by CVE-2020-1778?
CVE-2020-1778 affects OTRS versions 8.0.9 and prior.
5
How can I fix the vulnerability CVE-2020-1778?
To fix the vulnerability CVE-2020-1778, update your OTRS installation to a version that is not affected by the vulnerability.