CVE-2024-43446: Improper check of permissions in Generic Interface
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions.
This issue affects:
OTRS 7.0.X
OTRS 8.0.X OTRS 2023.X OTRS 2024.X
((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43446?
CVE-2024-43446 is a medium severity vulnerability that allows privilege escalation affecting ticket status management in OTRS.
How do I fix CVE-2024-43446?
To fix CVE-2024-43446, upgrade to OTRS versions 8.0.X or above, or apply the security patches issued by OTRS.
What versions of OTRS are affected by CVE-2024-43446?
CVE-2024-43446 affects OTRS versions 6.0.X, 7.0.X, 8.0.X, 2023.X, and 2024.X.
What kind of vulnerability is CVE-2024-43446?
CVE-2024-43446 is categorized as an improper privilege management vulnerability.
What are the potential impacts of CVE-2024-43446?
The potential impact of CVE-2024-43446 includes unauthorized changes to ticket statuses by users with read-only permissions.