CVE-2021-21437: Config Items are shown to users without permission
Published Mar 22, 2021
·Updated
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions
Affected Software
2 affected components
OTRS ITSMConfigurationManagement>=7.0.0<=7.0.24
OTRS OTRSCIsInCustomerFrontend>=7.0.0<=7.0.15
Remediation
Information
Update to ITSMConfigurationManagement 7.0.25 and OTRSCIsInCustomerFrontend 7.0.16.
Event History
Mar 22, 2021
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-21437.
2
What is the severity of CVE-2021-21437?
The severity of CVE-2021-21437 is medium with a severity value of 4.3.
3
Which software versions are affected by CVE-2021-21437?
OTRSCIsInCustomerFrontend versions 7.0.15 and prior, and ITSMConfigurationManagement versions 7.0.24 and prior are affected by CVE-2021-21437.
4
What is the impact of CVE-2021-21437?
Agents are able to see linked Config Items without permissions, which are defined in General Catalog.
5
How can I fix CVE-2021-21437?
Upgrade to a version of OTRSCIsInCustomerFrontend or ITSMConfigurationManagement that is not affected by CVE-2021-21437.