CVE-2024-43444

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Configurations

No configuration.

History

26 Aug 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-26 09:15

Updated : 2024-08-26 12:47


NVD link : CVE-2024-43444

Mitre link : CVE-2024-43444

CVE.ORG link : CVE-2024-43444


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File