Bugzilla – Bug 1179123
VUL-0: CVE-2020-1778: otrs: When using multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid
Last modified: 2021-02-03 22:32:35 UTC
CVE-2020-1778 When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-1778 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1778 https://otrs.com/release-notes/otrs-security-advisory-2020-16/
Product Affected: This issue affects OTRS 8.0.x. Problem: When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS: 8.0.9 and prior versions. This issue was found during internal product security testing or research. This issue has been assigned CVE-2020-1778.