CVE-2025-24390: Otrs AG Otrs
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X
Affected products
- Otrs AG Otrs: from 7.0, before 7.1 (fixed in 7.1); from 8.0, before 8.1 (fixed in 8.1); from 2023, before 2024 (fixed in 2024); from 2024, before 2025 (fixed in 2025)
Published 2025-01-27. Last modified 2026-06-17.