Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4088

Опубликовано: 21 фев. 2020
Источник: ubuntu
Приоритет: low
CVSS2: 4
CVSS3: 6.5

Описание

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

РелизСтатусПримечание
devel

not-affected

3.3.5-1
esm-apps/xenial

not-affected

3.3.5-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [3.3.5-1]]
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

ignored

end of life
saucy

not-affected

3.2.9-2
trusty

not-affected

3.3.5-1

Показывать по

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 6 лет назад

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

CVSS3: 6.5
debian
почти 6 лет назад

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OT ...

CVSS3: 6.5
github
почти 4 года назад

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

4 Medium

CVSS2

6.5 Medium

CVSS3