CVE-2020-1772: Debian Linux
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
Affected products
- Debian Debian Linux: version 8.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- Otrs Otrs: from 5.0.0, up to and including 5.0.41; from 6.0.0, up to and including 6.0.26; from 7.0.0, up to and including 7.0.15
Published 2020-03-27. Last modified 2026-06-17.