First published: Mon Mar 22 2021(Updated: )
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Itsmconfigurationmanagement | >=7.0.0<=7.0.24 | |
Otrs Otrscisincustomerfrontend | >=7.0.0<=7.0.15 |
Update to ITSMConfigurationManagement 7.0.25 and OTRSCIsInCustomerFrontend 7.0.16.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-21437.
The severity of CVE-2021-21437 is medium with a severity value of 4.3.
OTRSCIsInCustomerFrontend versions 7.0.15 and prior, and ITSMConfigurationManagement versions 7.0.24 and prior are affected by CVE-2021-21437.
Agents are able to see linked Config Items without permissions, which are defined in General Catalog.
Upgrade to a version of OTRSCIsInCustomerFrontend or ITSMConfigurationManagement that is not affected by CVE-2021-21437.