A vulnerability in OTRS Application Server allows session...
Moderate severity
Unreviewed
Published
Mar 10, 2025
to the GitHub Advisory Database
•
Updated Mar 24, 2025
Description
Published by the National Vulnerability Database
Mar 10, 2025
Published to the GitHub Advisory Database
Mar 10, 2025
Last updated
Mar 24, 2025
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
References