CVE-2025-24387 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an…
Medium CVSS: 4.8

CVE-2025-24387

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
 

This issue affects:

* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.x
Vendor
Otrs
Product
Otrs
CWE
CWE-1275
Yayın Tarihi
2025-03-10 10:15:14
Güncelleme
2025-03-24 14:11:20
Source Identifier
security@otrs.com
KEV Date Added
-

Kategoriler

Referanslar