Agents are able to lock the ticket without the Owner permission. Once the ticket is locked, it could be moved to the queue where the agent has rw permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 8.0.0 (including) | 8.0.16 (including) |