First published: Mon Jun 13 2022(Updated: )
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=7.0.0<7.0.35 | |
Otrs Otrs | >=8.0.0<8.0.23 |
Update to OTRS 8.0.23 or OTRS 7.0.35.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32741 is a vulnerability that allows an attacker to determine if a provided username exists and is valid by exploiting the Request New Password feature, based on the response time.
CVE-2022-32741 affects Otrs software versions 7.0.0 to 7.0.35 and 8.0.0 to 8.0.23.
CVE-2022-32741 has a severity rating of 5.3 (medium).
A patch has been released by Otrs to fix CVE-2022-32741, please refer to the official Otrs security advisory for more information.
You can find more information about CVE-2022-32741 in the Otrs security advisory at the following link: https://otrs.com/release-notes/otrs-security-advisory-2022-09/