Description
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to OTRSCIsInCustomerFrontend 7.0.15.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8710 | Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions. |
References
History
Tue, 17 Sep 2024 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Agent is able to link customer's Config Items without permission | Agent is able to link customer's Config Items without permission |
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-17T04:00:11.454Z
Reserved: 2020-12-29T00:00:00.000Z
Link: CVE-2021-21436
No data.
Status : Modified
Published: 2021-02-08T11:15:14.237
Modified: 2024-11-21T05:48:21.510
Link: CVE-2021-21436
No data.
OpenCVE Enrichment
No data.
EUVD