Name | CVE-2021-36095 |
Description | Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
OTRS, it's unclear to which extent Znuny might be affected since OTRS AG doesn't release
actionable information, also see https://github.com/znuny/Znuny/issues/128 and #993846