CVE Vulnerabilities

CVE-2024-23794

Published: Jul 15, 2024 | Modified: Jul 16, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting RequiredLock of AgentFrontend::Ticket::InlineEditing::Property###Watch in the system configuration.This issue affects OTRS: 

  • 8.0.X
  • 2023.X
  • from 2024.X through 2024.4.x

Affected Software

Name Vendor Start Version End Version
Otrs Otrs 8.0.0 (including) 2024.5.2 (excluding)

References