CVE-2019-18179

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Mailing List, Third Party Advisory
References () https://community.otrs.com/security-advisory-2019-14-security-update-for-otrs-framework/ - Patch, Vendor Advisory () https://community.otrs.com/security-advisory-2019-14-security-update-for-otrs-framework/ - Patch, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2020/01/msg00000.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/01/msg00000.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html - () https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html -

31 Aug 2023, 03:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html -

Information

Published : 2020-01-06 20:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-18179

Mitre link : CVE-2019-18179

CVE.ORG link : CVE-2019-18179


JSON object : View

Products Affected

debian

  • debian_linux

opensuse

  • leap
  • backports_sle

otrs

  • otrs