CVE-2021-21436

Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
References
Configurations

Configuration 1

cpe:2.3:a:otrs:cis_in_customer_frontend:*:*:*:*:*:*:*:*

Information

Published : 2021-02-08 11:15

Updated : 2021-02-10 06:23


NVD link : CVE-2021-21436

Mitre link : CVE-2021-21436

Products Affected
CWE
CWE-276

Incorrect Default Permissions