CVE-2025-24390 Information

Description

A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X
OTRS 2023.X
OTRS 2024.X

Reference

https://otrs.com/release-notes/otrs-security-advisory-2025-04/

Share on: