CVE-2024-43444 HIGH

CVE-2024-43444: Passwords are written to Admin Log Module

Vendor Otrs Ag
Product OTRS
Weakness CWE-532 · Sensitive info in logs
Published August 26, 2024
Last update August 29, 2024

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

Key dates

02Disclosure timeline

August 26, 2024 CVE published
August 29, 2024 Record updated