CVE-2021-21438: FAQ articles are shown to users without permission
Published Mar 22, 2021
·Updated
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
Affected Software
2 affected components
OTRS FAQ>=6.0.0<6.0.29
OTRS OTRS>=7.0.0<7.0.24
Remediation
Information
Update to OTRS 7.0.25.
Event History
Mar 22, 2021
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-21438.
2
What is the severity of CVE-2021-21438?
The severity of CVE-2021-21438 is medium, with a severity value of 4.3.
3
Which software versions are affected by CVE-2021-21438?
FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions are affected by CVE-2021-21438.
4
How can agents see linked FAQ articles without permissions?
Agents can see linked FAQ articles without permissions by exploiting the vulnerability in FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
5
Is there a fix for CVE-2021-21438?
Yes, the fix for CVE-2021-21438 is available in later versions of FAQ and OTRS.