CVE-2019-12746
Summary
| CVE | CVE-2019-12746 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 14:15:00 UTC |
| Updated | 2023-08-31 03:15:00 UTC |
| Description | An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2020:1475-1: moderate: Recommended updat |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2020:0551-1: moderate: Recommended updat |
SUSE |
lists.opensuse.org |
|
| [SECURITY] [DLA 3551-1] otrs2 security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 1877-1] otrs2 security update |
CONFIRM |
lists.debian.org |
Mailing List, Third Party Advisory |
| Security Advisory 2019-10: Security Update for OTRS Framework - ((OTRS)) Community Edition |
CONFIRM |
community.otrs.com |
Patch, Vendor Advisory |
| Release and Security Notes Archive | community.otrs.com |
MISC |
www.otrs.com |
Release Notes |
| [security-announce] openSUSE-SU-2020:1509-1: moderate: Recommended updat |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 6000085 Debian Security Update for otrs2 (DLA 3551-1)