CVE-2022-32741: Information disclosure in Request New Password feature
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-32741?
CVE-2022-32741 is a vulnerability that allows an attacker to determine if a provided username exists and is valid by exploiting the Request New Password feature, based on the response time.
How does CVE-2022-32741 affect Otrs software?
CVE-2022-32741 affects Otrs software versions 7.0.0 to 7.0.35 and 8.0.0 to 8.0.23.
What is the severity of CVE-2022-32741?
CVE-2022-32741 has a severity rating of 5.3 (medium).
How can I fix CVE-2022-32741?
A patch has been released by Otrs to fix CVE-2022-32741, please refer to the official Otrs security advisory for more information.
Where can I find more information about CVE-2022-32741?
You can find more information about CVE-2022-32741 in the Otrs security advisory at the following link: https://otrs.com/release-notes/otrs-security-advisory-2022-09/