Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
Solution:
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2021-04/ | vendor advisory |