CVE-2020-1777

NameCVE-2020-1777
DescriptionAgent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside the tickets, when system is configured to mask real agent names. This issue affects OTRS; 7.0.21 and prior versions, 8.0.6 and prior versions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
otrs2 (PTS)buster/non-free6.0.16-2fixed
bullseye/non-free6.0.30-2fixed
sid/non-free6.0.32-2fixed
stretch/non-free (security), stretch/non-free5.0.16-1+deb9u6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
otrs2source(unstable)(not affected)

Notes

- otrs2 <not-affected> (Only affects 7.x and 8.x)
https://otrs.com/release-notes/otrs-security-advisory-2020-15/

Search for package or bug name: Reporting problems