CVE-2022-3501: Information exposure of template content due to missing check of permissions
Published Oct 17, 2022
·Updated
Article template contents with sensitive data could be accessed from agents without permissions.
Affected Software
1 affected component
OTRS OTRS>=8.0.0<8.0.26
Remediation
Information
Update to OTRS 8.0.26
Event History
Oct 17, 2022
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-3501?
CVE-2022-3501 is a vulnerability that allows unauthorized access to article template contents with sensitive data in OTRS.
2
How severe is CVE-2022-3501?
CVE-2022-3501 has a severity score of 7.5, which is considered high.
3
What software is affected by CVE-2022-3501?
OTRS version 8.0.0 to 8.0.26 is affected by CVE-2022-3501.
4
How can I fix CVE-2022-3501?
To fix CVE-2022-3501, you should update OTRS to a version beyond 8.0.26 or apply the necessary security patches provided by OTRS.
5
Where can I find more information about CVE-2022-3501?
You can find more information about CVE-2022-3501 in the OTRS security advisory 2022-14: [OTRS Security Advisory 2022-14](https://otrs.com/release-notes/otrs-security-advisory-2022-14/)