CVE-2020-1772
7.5
HIGH
CVSS 3.1
EPSS 0.45%
Description
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
How to fix CVE-2020-1772
To remediate CVE-2020-1772, upgrade the affected package to a fixed version below.
- Debian/otrs2—upgrade to 6.0.27-1 or later
Is CVE-2020-1772 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 6.0.27-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |