A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.x
References
Link | Resource |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2025-05/ | Vendor Advisory |
Configurations
History
24 Mar 2025, 14:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://otrs.com/release-notes/otrs-security-advisory-2025-05/ - Vendor Advisory | |
CPE | cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* | |
CWE | CWE-352 | |
Summary |
|
|
First Time |
Otrs
Otrs otrs |
10 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-10 10:15
Updated : 2025-03-24 14:11
NVD link : CVE-2025-24387
Mitre link : CVE-2025-24387
CVE.ORG link : CVE-2025-24387
JSON object : View
Products Affected
otrs
- otrs