CVE-2023-38058: Tickets can be moved without permissions
Published Jul 24, 2023
·Updated
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.
Affected Software
1 affected component
OTRS OTRS>=8.0.0<8.0.35
Remediation
Information
Update to OTRS 8.0.35
Event History
Jul 24, 2023
CVE Published
via MITRE·08:28 AM
Data Sourced
via MITRE·08:28 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-38058?
CVE-2023-38058 is an improper privilege check vulnerability in the OTRS ticket move action in the agent interface.
2
How does CVE-2023-38058 impact OTRS?
CVE-2023-38058 allows any authenticated attacker to perform a ticket move without the necessary permission.
3
What is the severity of CVE-2023-38058?
CVE-2023-38058 has a severity of medium with a CVSS score of 4.3.
4
Which software versions of OTRS are affected by CVE-2023-38058?
CVE-2023-38058 affects OTRS versions 8.0.X before 8.0.35.
5
How can I fix CVE-2023-38058 in OTRS?
To fix CVE-2023-38058, it is recommended to upgrade OTRS to version 8.0.35 or later.