Vulnerability Description
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Custom Contact Fields | >= 8.0.0, < 8.0.12 |
Related Weaknesses (CWE)
References
- https://otrs.com/release-notes/otrs-security-advisory-2022-02/Vendor Advisory
- https://otrs.com/release-notes/otrs-security-advisory-2022-02/Vendor Advisory
FAQ
What is CVE-2022-0474?
CVE-2022-0474 is a vulnerability with a CVSS score of 2.4 (LOW). Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affect...
How severe is CVE-2022-0474?
CVE-2022-0474 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0474?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Custom Contact Fields.