Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-36097

Опубликовано: 18 окт. 2021
Источник: debian

Описание

Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
otrsnot-affectedpackage

Примечания

  • znuny forked from OTRS with 6.x, but this issue is specific to OTRS 8.x

Связанные уязвимости

CVSS3: 3.5
nvd
больше 4 лет назад

Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

CVSS3: 4.3
github
больше 3 лет назад

Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.