CVE-2019-13458
Summary
| CVE | CVE-2019-13458 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 14:15:00 UTC |
| Updated | 2023-08-31 03:15:00 UTC |
| Description | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Otrs | Otrs | All | All | All | All |
| Application | Otrs | Otrs | All | All | All | All |
| Application | Otrs | Otrs | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2020:1475-1: moderate: Recommended updat | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2020:0551-1: moderate: Recommended updat | SUSE | lists.opensuse.org | |
| [SECURITY] [DLA 3551-1] otrs2 security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 1877-1] otrs2 security update | CONFIRM | lists.debian.org | Mailing List, Third Party Advisory |
| Security Advisory 2019-12: Security Update for OTRS Framework - ((OTRS)) Community Edition | CONFIRM | community.otrs.com | Patch, Vendor Advisory |
| Release and Security Notes Archive | community.otrs.com | MISC | www.otrs.com | Release Notes |
| [security-announce] openSUSE-SU-2020:1509-1: moderate: Recommended updat | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 6000085 Debian Security Update for otrs2 (DLA 3551-1)