CVE-2021-36097

NameCVE-2021-36097
DescriptionAgents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
otrssource(unstable)(not affected)

Notes

- otrs <not-affected> (OTRS 8.x specific)
znuny forked from OTRS with 6.x, but this issue is specific to OTRS 8.x

Search for package or bug name: Reporting problems