Candidate: CVE-2020-1772 PublicDate: 2020-03-27 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1772 https://otrs.com/release-notes/otrs-security-advisory-2020-09/ Description: It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_otrs2: upstream: https://github.com/OTRS/otrs/commit/c0255365d5c455272b2b9e7bb1f6c96c3fce441b (otrs 6) upstream: https://github.com/OTRS/otrs/commit/2628464f659c39fafbc32147d569553eb07d41d7 (otrs 5) upstream_otrs2: needs-triage precise/esm_otrs2: DNE trusty_otrs2: ignored (out of standard support) trusty/esm_otrs2: DNE xenial_otrs2: ignored (end of standard support, was needs-triage) bionic_otrs2: needs-triage eoan_otrs2: ignored (reached end-of-life) focal_otrs2: needs-triage groovy_otrs2: not-affected (6.0.27-1) hirsute_otrs2: not-affected (6.0.27-1) impish_otrs2: not-affected (6.0.27-1) jammy_otrs2: not-affected (6.0.27-1) devel_otrs2: not-affected (6.0.27-1)