Security Advisory
CVE-2021-36097
3.5
LOW
Vulnerability Description
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.
Published Date
October 18, 2021
Official Source
NIST NVD Advisory