CVE-2022-1004: Information disclosure in the External Interface
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1004.
What is the title of the vulnerability?
The title of the vulnerability is 'Accounted time is shown in the Ticket Detail View (External Interface) even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.'
What is the description of the vulnerability?
The description of the vulnerability states that accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.
Which software versions are affected by this vulnerability?
The vulnerability affects OTRS versions 7.0.0 to 7.0.33 and 8.0.0 to 8.0.20.
What is the severity of CVE-2022-1004?
The severity of CVE-2022-1004 is medium (4.3).
How can I fix CVE-2022-1004?
To fix CVE-2022-1004, update OTRS to version 7.0.34 or 8.0.21 or apply the provided patches from the OTRS Security Advisory 2022-06.