VulnerabilityModified
CVE-2019-13458
An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
MEDIUM 6.5EPSS 1.55%
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- otrs/otrs · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://community.otrs.com/security-advisory-2019-12-security-update-for-otrs-framework/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://www.otrs.com/category/release-and-security-notes-en/Release Notes
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlBroken Link
- https://community.otrs.com/security-advisory-2019-12-security-update-for-otrs-framework/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://www.otrs.com/category/release-and-security-notes-en/Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.