CVE Vulnerabilities

CVE-2021-21437

Published: Mar 22, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions

Affected Software

Name Vendor Start Version End Version
Itsmconfigurationmanagement Otrs 7.0.0 (including) 7.0.24 (including)
Otrscisincustomerfrontend Otrs 7.0.0 (including) 7.0.15 (including)

References