Description
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
References
https://otrs.com/release-notes/otrs-security-advisory-2021-20/
Release NotesVendor Advisory
https://otrs.com/release-notes/otrs-security-advisory-2021-20/
Release NotesVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
3.5 · Low
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-18T05:15:07.413Z
4 years agoLast modified
2024-11-21T05:13:09.143Z
1 year ago