[Bug 1168029] New: VUL-0: CVE-2020-1772: otrs: Lost Password requests with wildcard values could allow attacker to retrieve valid Token
http://bugzilla.opensuse.org/show_bug.cgi?id=1168029 Bug ID: 1168029 Summary: VUL-0: CVE-2020-1772: otrs: Lost Password requests with wildcard values could allow attacker to retrieve valid Token Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.2 Hardware: Other URL: https://smash.suse.de/issue/256040/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Basesystem Assignee: chris@computersalat.de Reporter: abergmann@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2020-1772 It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-1772 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1772 https://otrs.com/release-notes/otrs-security-advisory-2020-09/ -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1168029 http://bugzilla.opensuse.org/show_bug.cgi?id=1168029#c1 Christian Wittmer <chris@computersalat.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CONFIRMED --- Comment #1 from Christian Wittmer <chris@computersalat.de> --- ongoing work ... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1168029 http://bugzilla.opensuse.org/show_bug.cgi?id=1168029#c6 Christian Wittmer <chris@computersalat.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|CONFIRMED |IN_PROGRESS CC| |security-team@suse.de Flags| |needinfo?(security-team@sus | |e.de) --- Comment #6 from Christian Wittmer <chris@computersalat.de> --- can we close this ? -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1168029 http://bugzilla.opensuse.org/show_bug.cgi?id=1168029#c7 Alexandros Toptsoglou <atoptsoglou@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED CC| |atoptsoglou@suse.com Resolution|--- |FIXED Flags|needinfo?(security-team@sus | |e.de) | --- Comment #7 from Alexandros Toptsoglou <atoptsoglou@suse.com> --- Done -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com