Security Advisory 2020-01
Security Advisory 2020-02
Security Advisory 2020-03
Security Advisory 2020-04 – betrifft nur OTRS 7
Security Advisory 2020-05 – Risk Level: Medium
Security Advisory 2020-06 (Auto-complete in form login screens. Risk Level: 3.5 LOW)
Security Advisory 2020-07 (Information disclosure in support bundle files. Risk Level: 2.4 LOW)
Security Advisory 2020-08 (Possible XSS in Customer user address book. Risk Level: 4.6 MEDIUM)
Security Advisory 2020-09 (It’s possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. Risk Level: 6.5 MEDIUM)
Security Advisory 2020-10 (It’s possible that an authenticated user guess other session IDs based on its own. Also it’s possible to guess a password reset token or an automated password generated. Risk Level: 7.3 HIGH)
Security Advisory 2020-11 (When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it’s possible to mix them and to send private key to the third-party instead of public key. Risk Level: 4.5 MEDIUM)
Security Advisory 2020-12 – betrifft nur OTRS 7 und 8
Security Advisory 2020-13 (Invalidating or changing user does not invalidate session. Risk Level: 3.5 LOW)
Security Advisory 2020-14 (OTRS uses jquery version 3.4.1, which is vulnerable to cross-site scripting (XSS). Risk Level: 6.3 / 6.5 MEDIUM)
Security Advisory 2020-15 – betrifft nur OTRS 7 und 8
Security Advisory 2020-16 – betrifft nur OTRS 8