When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1778.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "8.0.9" } ] } ]