The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.
References
Link | Resource |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2023-08/ | Vendor Advisory |
https://otrs.com/release-notes/otrs-security-advisory-2023-08/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://otrs.com/release-notes/otrs-security-advisory-2023-08/ - Vendor Advisory |
19 Oct 2023, 17:42
Type | Values Removed | Values Added |
---|---|---|
First Time |
Otrs otrs
Otrs |
|
References | (MISC) https://otrs.com/release-notes/otrs-security-advisory-2023-08/ - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:* |
16 Oct 2023, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-16 09:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-38059
Mitre link : CVE-2023-38059
CVE.ORG link : CVE-2023-38059
JSON object : View
Products Affected
otrs
- otrs
CWE