CVE-2025-24387: Missing CSRF protection
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
OTRS 7.0.X OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.x
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24387?
CVE-2025-24387 is classified as a medium severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2025-24387?
To fix CVE-2025-24387, ensure that proper attributes are set for sensitive cookies in your OTRS application settings.
Which versions of OTRS are affected by CVE-2025-24387?
CVE-2025-24387 affects OTRS versions 7.0.x, 8.0.x, 2023.x, 2024.x, and 2025.x.
What impact does CVE-2025-24387 have on systems?
CVE-2025-24387 allows potential session hijacking, leading to unauthorized access and data exposure.
Is there an official advisory for CVE-2025-24387?
Yes, there is an official security advisory regarding CVE-2025-24387 published by OTRS.