CVE-2022-32741 — Sensitive Information Exposure in Otrs
Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateJun 14
Description
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-4j4j-3vh8-c9x5: Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time↗2022-06-14
OSV▶
CVE-2022-32741: Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time↗2022-06-13