CVE-2024-23792: Insufficient access control
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.
This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 7.0.49 - Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Patch 2024.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23792?
CVE-2024-23792 is considered a moderate severity vulnerability due to its potential for unauthorized file manipulation.
How do I fix CVE-2024-23792?
To fix CVE-2024-23792, users should upgrade to OTRS versions 7.0.49 or later, or 8.0.0 or later.
What impact does CVE-2024-23792 have on user security?
CVE-2024-23792 allows a malicious user to impersonate another user and add attachments, compromising the integrity of ticket comments.
Who is affected by CVE-2024-23792?
CVE-2024-23792 affects users of OTRS versions prior to 7.0.49 and versions between 8.0.0 and 2024.1.1.
Is authentication required to exploit CVE-2024-23792?
Yes, exploitation of CVE-2024-23792 requires the attacker to be a logged-in user who knows the UUID of the comment being modified.