The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 7.0.0 (including) | 7.0.14 (including) |
Otrs2 | Ubuntu | bionic | * |
Otrs2 | Ubuntu | eoan | * |
Otrs2 | Ubuntu | groovy | * |
Otrs2 | Ubuntu | hirsute | * |
Otrs2 | Ubuntu | impish | * |
Otrs2 | Ubuntu | trusty | * |
Otrs2 | Ubuntu | xenial | * |