Description: | Summary: The remote host is missing an update for the Debian 'otrs2' package(s) announced via the DLA-3551-1 advisory.
Vulnerability Insight: Multiple vulnerabilities were found in otrs2, the Open-Source Ticket Request System, which could lead to impersonation, denial of service, information disclosure, or execution of arbitrary code.
CVE-2019-11358
A Prototype Pollution vulnerability was discovered in OTRS' embedded jQuery 3.2.1 copy, which could allow sending drafted messages as wrong agent.
This vulnerability is also known as OSA-2020-05.
CVE-2019-12248
Matthias Terlinde discovered that when an attacker sends a malicious email to an OTRS system and a logged in agent user later quotes it, the email could cause the browser to load external image resources.
A new configuration setting Ticket::Frontend::BlockLoadingRemoteContent has been added as part of the fix. It controls whether external content should be loaded, and it is disabled by default.
This vulnerability is also known as OSA-2019-08.
CVE-2019-12497
Jens Meister discovered that in the customer or external frontend, personal information of agents, like Name and mail address in external notes, could be disclosed.
New configuration settings Ticket::Frontend::CustomerTicketZoom###DisplayNoteFrom has been added as part of the fix. It controls if agent information should be displayed in external note sender field, or be substituted with a different generic name. Another option named Ticket::Frontend::CustomerTicketZoom###DefaultAgentName can then be used to define the generic agent name used in the latter case. By default, previous behavior is preserved, in which agent information is divulged in the external note From field, for the sake of backwards compatibility.
This vulnerability is also known as OSA-2019-09.
CVE-2019-12746
A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then potentially abused in order to impersonate the agent user.
This vulnerability is also known as OSA-2019-10.
CVE-2019-13458
An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS tags in templates in order to disclose hashed user passwords.
This vulnerability is also known as OSA-2019-12.
CVE-2019-16375
An attacker who is logged into OTRS as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent compose an answer to the original article.
This vulnerability is also known as OSA-2019-13.
CVE-2019-18179
An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, which are in the queue where attacker doesn't have permissions.
This vulnerability is also known as OSA-2019-14.
CVE-2019-18180
OTRS can be put into an endless loop by providing filenames with overly long extensions. This applies to the PostMaster (sending in ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'otrs2' package(s) on Debian 10.
Solution: Please install the updated package(s).
CVSS Score: 9.0
CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
|