Bugzilla – Bug 864613
VUL-0: CVE-2013-3551: otrs: privlege escalation
Last modified: 2014-03-26 11:29:19 UTC
CVE-2013-3551 An attacker with a valid agent login could manipulate URLs in the ticket watch mechanism to see contents of tickets they are not permitted to see. References: http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-3551.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3551
bugbot adjusting priority
perhaps chris can do it
http://www.otrs.com/security-advisory-2013-03/?lang=de 12.3 not affected by this BUG: ./12.3/noarch/otrs-3.1.20-26.9.1.noarch.rpm > 3.1.16 ./12.3/noarch/otrs-itsm-3.1.10-26.9.1.noarch.rpm > 3.1.9 13.1 not affected by this BUG ./13.1/src/otrs-3.2.15-31.5.1.src.rpm > 3.2.7 ./13.1/noarch/otrs-itsm-3.2.9-31.5.1.noarch.rpm > 3.2.5