Bug ID 1227777
Summary VUL-0: CVE-2024-6540: otrs: improper filtering of fields when using the export function in the ticket overview of the external interface could allow access to sensitive information
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/414103/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee chris@computersalat.de
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Improper filtering of fields when using the export function in the ticket
overview of the external interface could allow an authorized user to download a
list of tickets containing information about tickets of other customers. The
problem only occurs if the TicketSearchLegacyEngine has been disabled by the
administrator.
This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-6540
https://www.cve.org/CVERecord?id=CVE-2024-6540
https://otrs.com/release-notes/otrs-security-advisory-2024-07/


You are receiving this mail because: