It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2198-1 | otrs2 security update |
![]() |
DLA-3551-1 | otrs2 security update |
![]() |
EUVD-2020-12598 | It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. |
Fixes
Solution
Upgrade to OTRS 7.0.16, ((OTRS)) Community Edition 6.0.27, 5.0.42 Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/c0255365d5c455272b2b9e7bb1f6c96c3fce441b Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/96cc7826d6ce260204ff629fc968edd2787b7f6b
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-16T23:25:42.434Z
Reserved: 2019-11-29T00:00:00
Link: CVE-2020-1772

No data.

Status : Modified
Published: 2020-03-27T13:15:15.393
Modified: 2024-11-21T05:11:21.497
Link: CVE-2020-1772

No data.

No data.