CVE-2021-36097: Agents are able to lock the ticket without the "Owner" permission
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-36097?
CVE-2021-36097 is a vulnerability that allows agents to lock a ticket without the "Owner" permission, giving them full control over the ticket.
What software versions are affected by CVE-2021-36097?
CVE-2021-36097 affects OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
What is the severity of CVE-2021-36097?
CVE-2021-36097 has a severity keyword of 'medium' and a severity value of 4.3.
How can I fix CVE-2021-36097?
To fix CVE-2021-36097, users should update OTRS to version 8.0.17 or a later secure version.
Where can I find more information about CVE-2021-36097?
More information about CVE-2021-36097 can be found at the following link: [OTRS Security Advisory 2021-20](https://otrs.com/release-notes/otrs-security-advisory-2021-20/).