SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1776

When an agent user is renamed or set to invalid the session belonging to the user is keept active.

MEDIUM 4.3EPSS 0.88%

Does this matter?

Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.

Description

When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions. OTRS: 7.0.18 and prior versions, 8.0.4. and prior versions.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-613
Affected
otrs/otrs
Source
security@otrs.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.