CVE-2020-1768Insufficient Session Expiration in AG Otrs

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 45.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 7
Latest updateMay 24

Description

The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

NVDotrs/otrs7.0.07.0.14
CVEListV5otrs_ag/otrs7.0.x7.0.14

🔴Vulnerability Details

3
GHSA
GHSA-chcp-v68p-g2px: The external frontend system uses numerous background calls to the backend2022-05-24
CVEList
External Interface does not invalidate session2020-02-07
OSV
CVE-2020-1768: The external frontend system uses numerous background calls to the backend2020-02-07

📋Vendor Advisories

1
Debian
CVE-2020-1768: otrs2 - The external frontend system uses numerous background calls to the backend. Each...2020
CVE-2020-1768 — Insufficient Session Expiration | cvebase