Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63m6-fqgg-rv45

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

It's possible that an authenticated user guess other session IDs based on its own. Also it's possible to guess a password reset token or an automated password generated. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

It's possible that an authenticated user guess other session IDs based on its own. Also it's possible to guess a password reset token or an automated password generated. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

EPSS

Процентиль: 69%
0.00606
Низкий

8.1 High

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 6 лет назад

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVSS3: 7.3
nvd
почти 6 лет назад

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVSS3: 7.3
debian
почти 6 лет назад

An attacker with the ability to generate session IDs or password reset ...

suse-cvrf
больше 5 лет назад

Recommended update for otrs

suse-cvrf
почти 6 лет назад

Recommended update for otrs

EPSS

Процентиль: 69%
0.00606
Низкий

8.1 High

CVSS3

Дефекты

CWE-331