CVE-2020-1773

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
27/03/2020
Last modified:
31/08/2023

Description

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:* 5.0.0 (including) 5.0.41 (including)
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:* 6.0.0 (including) 6.0.26 (including)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.15 (including)