Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0474

Опубликовано: 07 фев. 2022
Источник: nvd
CVSS3: 2.4
CVSS3: 3.5
CVSS2: 3.5
EPSS Низкий

Описание

Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:otrs:custom_contact_fields:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.12 (исключая)

EPSS

Процентиль: 43%
0.00209
Низкий

2.4 Low

CVSS3

3.5 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200
CWE-200

Связанные уязвимости

CVSS3: 2.4
ubuntu
около 4 лет назад

Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.

github
почти 4 года назад

Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.

EPSS

Процентиль: 43%
0.00209
Низкий

2.4 Low

CVSS3

3.5 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200
CWE-200