image

Security Advisories

Dear reader,

The following security fix/es was/were made:

OTRS Security Advisory 2022-01

ID: OSA-2022-01
Date: 2022-02-07
Title: Dynamic field error message is vulnerable to XSS
Severity: 3.8 LOW
Product: OTRS 7.0.x
Fixed in: OTRS 7.0.32
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
References: CVE-2022-0473


OTRS Security Advisory 2022-02

ID: OSA-2022-02
Date: 2022-02-07
Title: Disclosure of mail addresses
Severity: 2.4 LOW
Product: OTRSCustomContactFields 8.0.x,
Fixed in: OTRS 8.0.12
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
References: CVE-2022-0474


OTRS Security Advisory 2022-04

ID: OSA-2022-04
Date: 2022-02-07
Title: Several vulnerabilities in third-party npm modules
Severity: 5.8 MEDIUM
Product: OTRS 8.0.x
Fixed in: OTRS 8.0.19
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
References: CVE-2021-3803 / CVE-2021-3807 / CVE-2021-23368


To read the entire Security Advisory/Advisories, please follow this link:
https://otrs.com/overview-release-notes-security-advisories/security-advisories/ 
Kind regards, 
Your OTRS release team 
image

Subscribe to the OTRS Newsletter.

Read about OTRS service management solutions, product features, and interesting tips from our experts every month. Simply select your desired language.

 
 
Facebook Twitter LinkedIn YouTube Instagram