Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2021-14/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing list |