CVE-2021-21443 PUBLISHED

Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

EPSS 0.22% · 44.4th percentile

Risk Scores

EPSS Score
0.22%
44.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSotrs25.0.6-1, 5.0.3-1, 4.0.10-1
Ubuntu:20.04:LTSotrs26.0.23-2, 6.0.24-1, 6.0.25-1
Ubuntu:18.04:LTSotrs26.0.5-1, 0, 5.0.23-1
Ubuntu:22.04:LTSotrs26.0.32-6, 6.1.2-1, 6.2.2-2

Timeline

References

Open in Interactive Console →