Headline
CVE-2023-6254: OTRS Security Advisory 2023-11
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.
Release Note
Please read carefully and check if the version of your OTRS system is affected by this vulnerability.
Please send information regarding vulnerabilities in OTRS to: [email protected]
PGP Key
- pub 2048R/9C227C6B 2011-03-21
- uid OTRS Security Team <[email protected]>
- GPG Fingerprint E330 4608 DA6E 34B7 1551 C244 7F9E 44E9 9C22 7C6B
Security Advisory Details
- ID: OSA-2023-11
- Date: 2023-11-07
- Title: Password is send back to client
- Severity: 8.1 HIGH
- Product: OTRS 8.0.x
- Fixed in: OTRS 2023.1.1
- CVSS: FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- References: CVE-2023-6254
OSA-2023-11 CVE-2023-6254 Password is sent back to client
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are sending back to the client in the server response.
PRODUCT AFFECTED:
This issue affects
OTRS: from 8.0.X through 8.0.37
PROBLEM:
CWE-522 Insufficiently Protected Credentials CWE-522
Impact:
CAPEC-555 Remote Services with Stolen Credentials CAPEC-555
Product Status
OTRS AG OTRS » AgentInterface, ExternalInterface
Default status is affected
from 8.0.1 through 8.0.37
SOLUTION:
Update to OTRS Patch 2023.1.1
MODIFICATION HISTORY:
- —
CVSS SCORE:
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
RISK LEVEL:
LOW
ACKNOWLEDGEMENTS:
Special thanks to Matthias Püschel for reporting these vulnerability.