Vulnerability Description
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting 'RequiredLock' of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' in the system configuration.This issue affects OTRS: * 8.0.X * 2023.X * from 2024.X through 2024.4.x
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 8.0.0, < 2024.5.2 |
Related Weaknesses (CWE)
References
- https://otrs.com/release-notes/otrs-security-advisory-2024-06/Vendor Advisory
- https://otrs.com/release-notes/otrs-security-advisory-2024-06/Vendor Advisory
FAQ
What is CVE-2024-23794?
CVE-2024-23794 is a vulnerability with a CVSS score of 5.2 (MEDIUM). An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access t...
How severe is CVE-2024-23794?
CVE-2024-23794 has been rated MEDIUM with a CVSS base score of 5.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23794?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs.