Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13458

Опубликовано: 21 авг. 2019
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
otrs2fixed6.0.20-1package
otrs2ignoredstretchpackage

Примечания

  • https://community.otrs.com/security-advisory-2019-12-security-update-for-otrs-framework/

  • OTRS 6.0: https://github.com/OTRS/otrs/commit/69430f260d52e5a7afc185048da0cfc2eef2659a

  • OTRS 5.0: https://github.com/OTRS/otrs/commit/0e26066dfff8efff0039da13e29609ca7f00d9a2

EPSS

Процентиль: 62%
0.00437
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

CVSS3: 6.5
nvd
почти 6 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

CVSS3: 6.5
github
около 3 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

suse-cvrf
почти 5 лет назад

Recommended update for otrs

suse-cvrf
больше 5 лет назад

Recommended update for otrs

EPSS

Процентиль: 62%
0.00437
Низкий