CVE-2025-24391
Last modified
CVE-2025-24391 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24391?
How severe is CVE-2025-24391?
How do I fix CVE-2025-24391?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24385Dell Unity, version(s) 5.4 and prior, contain(s) an Improper…7.8
- CVE-2025-24386Dell Unity, version(s) 5.4 and prior, contain(s) an Improper…7.8
- CVE-2025-24387A vulnerability in OTRS Application Server allows session hi…6.5
- CVE-2025-24388A vulnerability in the OTRS Admin Interface and Agent Interf…3.8
- CVE-2025-24389Certain errors of the upstream libraries will insert sensiti…6.3
- CVE-2025-24390A vulnerability in OTRS Application Server and reverse proxy…6.8
- CVE-2025-24397An incorrect permission check in Jenkins GitLab Plugin 1.9.6…4.3
- CVE-2025-24398Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.…8.8
- CVE-2025-24399Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3…8.8
- CVE-2025-2440CWE-922: Insecure Storage of Sensitive Information vulnerabi…4.2
- CVE-2025-24400Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both…4.3
- CVE-2025-24401Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_…6.8
Are you affected by CVE-2025-24391?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
