CVE Vulnerabilities

CVE-2021-36097

Incorrect Privilege Assignment

Published: Oct 18, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Agents are able to lock the ticket without the Owner permission. Once the ticket is locked, it could be moved to the queue where the agent has rw permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Otrs Otrs 8.0.0 (including) 8.0.16 (including)

Potential Mitigations

References