CVE-2022-32741Sensitive Information Exposure in Otrs

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateJun 14

Description

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDotrs/otrs7.0.07.0.35+1
CVEListV5otrs_ag/otrs7.0.x7.0.34+1

🔴Vulnerability Details

3
GHSA
GHSA-4j4j-3vh8-c9x5: Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time2022-06-14
OSV
CVE-2022-32741: Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time2022-06-13
CVEList
Information disclosure in Request New Password feature2022-06-13
CVE-2022-32741 — Sensitive Information Exposure in Otrs | cvebase