Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

openSUSE: 2020:0551-1 Moderate: OTRS Information Disclosure and XSS

opensuse
Calendar Grey April 25, 2020
Dist Opensuse Esm H88
openSUSE Safety Enhancement: Suggested upgrade for otrs addresses 18 vulnerabilities, enhancing both security and efficiency.
An update that fixes 18 vulnerabilities is now available.

Description

Otrs was updated to 5.0.42, fixing lots of bugs and security issues:

https://otrs.com/es/soluciones-de-software-otrs/otrs-community-edition/

- CVE-2020-1773 boo#1168029 OSA-2020-10:

* Session / Password / Password token leak An attacker with the ability

to generate session IDs or password reset tokens, either by being able

to authenticate or by exploiting OSA-2020-09, may be able to predict

other users session IDs, password reset tokens and automatically

generated passwords.

- CVE-2020-1772 boo#1168029 OSA-2020-09:

* Information Disclosure It’s possible to craft Lost Password requests

with wildcards in the Token value, which allows attacker to retrieve

valid Token(s), generated by users which already requested new

passwords.

- CVE-2020-1771 boo#1168030 OSA-2020-08:

* Possible XSS in Customer user address book Attacker is able craft an

article with a link to the customer address book with...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-551=1

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2020-551=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2020-551=1

Package List

- openSUSE Leap 15.1 (noarch):

otrs-5.0.42-lp151.2.3.1

otrs-doc-5.0.42-lp151.2.3.1

otrs-itsm-5.0.42-lp151.2.3.1

- openSUSE Backports SLE-15-SP1 (noarch):

otrs-5.0.42-bp151.3.3.1

otrs-doc-5.0.42-bp151.3.3.1

otrs-itsm-5.0.42-bp151.3.3.1

- openSUSE Backports SLE-15 (noarch):

otrs-5.0.42-bp150.2.10.1

otrs-doc-5.0.42-bp150.2.10.1

otrs-itsm-5.0.42-bp150.2.10.1

References

https://www.suse.com/security/cve/CVE-2019-10067.html

https://www.suse.com/security/cve/CVE-2019-12248.html

https://www.suse.com/security/cve/CVE-2019-12497.html

https://www.suse.com/security/cve/CVE-2019-12746.html

https://www.suse.com/security/cve/CVE-2019-13457.html

https://www.suse.com/security/cve/CVE-2019-13458.html

https://www.suse.com/security/cve/CVE-2019-16375.html

https://www.suse.com/security/cve/CVE-2019-18179.html

https://www.suse.com/security/cve/CVE-2019-18180.html

https://www.suse.com/security/cve/CVE-2019-9752.html

https://www.suse.com/security/cve/CVE-2019-9892.html

https://www.suse.com/security/cve/CVE-2020-1765.html

https://www.suse.com/security/cve/CVE-2020-1766.html

https://www.suse.com/security/cve/CVE-2020-1769.html

https://www.suse.com/security/cve/CVE-2020-1770.html

https://www.suse.com/security/cve/CVE-2020-1771.html

https://www.suse.com/security/cve/CVE-2020-1772.html

https://www.suse.com/security/cve/CVE-2020-1773.html

https://bugzilla.suse.com/1122560

https://bugzilla.suse....

Read the Full Advisory

Announcement ID: openSUSE-SU-2020:0551-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here