Package        : otrs2
Version        : 3.3.18-1+deb8u14
CVE ID         : CVE-2019-11358
Debian Bug     : 927385


It was discovered that the jQuery version embedded in OTRS, a ticket
request system, was prone to a cross site scripting vulnerability in
jQuery.extend().

For Debian 8 "Jessie", this problem has been fixed in version
3.3.18-1+deb8u14.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2118-1: otrs2 security update

February 24, 2020
It was discovered that the jQuery version embedded in OTRS, a ticket request system, was prone to a cross site scripting vulnerability in jQuery.extend()

Summary

For Debian 8 "Jessie", this problem has been fixed in version
3.3.18-1+deb8u14.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : otrs2
Version : 3.3.18-1+deb8u14
CVE ID : CVE-2019-11358
Debian Bug : 927385

Related News