A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.x
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2025-05/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-03-10 10:15
Updated : 2025-03-24 14:11
NVD link : CVE-2025-24387
Mitre link : CVE-2025-24387
CVE.ORG link : CVE-2025-24387
JSON object : View
Products Affected
otrs
- otrs
