CVE-2021-36091Sensitive Information Exposure in AG Community Edition

Severity
4.3MEDIUMNVD
CNA3.5
EPSS
0.1%
top 67.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 24

Description

Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5otrs_ag/community_edition6.0.16.0.x*
NVDotrs/otrs6.0.06.0.32+1
CVEListV5otrs_ag/otrs7.0.x7.0.27

🔴Vulnerability Details

3
GHSA
GHSA-mxpc-p9xr-9j86: Agents are able to list appointments in the calendars without required permissions2022-05-24
CVEList
Unautorized access to the calendar appointments2021-07-26
OSV
CVE-2021-36091: Agents are able to list appointments in the calendars without required permissions2021-07-26

📋Vendor Advisories

1
Debian
CVE-2021-36091: otrs2 - Agents are able to list appointments in the calendars without required permissio...2021
CVE-2021-36091 — Sensitive Information Exposure | cvebase