CVE-2025-24390: Missing Cookie Flags
Published Jan 27, 2025
·Updated
A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions.
This issue affects:
OTRS 7.0.X
OTRS 8.0.X OTRS 2023.X OTRS 2024.X
Affected Software
1 affected component
OTRS OTRS>=7.0.0<=7.0.X, >=8.0.0<=8.0.X, >=2023.0<=2023.X, >=2024.0<=2024.X
Remediation
Information
Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
Event History
Jan 27, 2025
CVE Published
via MITRE·05:59 AM
Data Sourced
via MITRE·05:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24390?
CVE-2025-24390 has a high severity rating due to its potential for session hijacking.
2
How do I fix CVE-2025-24390?
To fix CVE-2025-24390, update your OTRS application to the latest version that addresses the cookie attribute settings.
3
Which versions of OTRS are affected by CVE-2025-24390?
CVE-2025-24390 affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X.
4
What is the impact of CVE-2025-24390 on users?
The impact of CVE-2025-24390 allows attackers to hijack user sessions, compromising sensitive data.
5
Are there any workarounds for CVE-2025-24390 before applying a fix?
A temporary workaround for CVE-2025-24390 includes reviewing and enhancing cookie security settings until a proper update is applied.