Security Advisories
Dear reader,

The following security fix/es was/were made:
OTRS Security Advisory 2021-18

ID: OSA-2021-18
Date: 2021-09-06
Title: User enumeration issue using "lost password" feature
Severity: 5.3 MEDIUM
Product: OTRS 7.0.x
Fixed in: OTRS 7.0.29
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References: CVE-2021-36095
OTRS Security Advisory 2021-17

ID: OSA-2021-17
Date: 2021-09-06
Title: XSS attack in appointment edit popup screen
Severity: 5.7. MEDIUM
Product: OTRS 7.0.x
Fixed in: OTRS 7.0.29
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
References: CVE-2021-36094
OTRS Security Advisory 2021-16

ID: OSA-2021-16
Date: 2021-09-06
Title: DoS attack using PostMaster filters
Severity: 5.3 MEDIUM
Product: OTRS 8.0.x, OTRS 7.0.x
Fixed in: OTRS 8.0.16, OTRS 7.0.29
FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References: CVE-2021-36093
To read the entire Security Advisory/Advisories, please follow this link:
https://otrs.com/overview-release-notes-security-advisories/security-advisories/
  
<https://pg183.keap-link003.com/api/v1/click/6579136176193536/4646958497005568>
Kind regards, 
Your OTRS release team
 <https://pg183.keap-link003.com/api/v1/click/4903041731264512/4646958497005568>
Subscribe to the OTRS Newsletter.

Read about OTRS service management solutions, product features, and interesting 
tips from our experts every month. Simply select your desired language.
German 
<https://pg183.keap-link003.com/api/v1/click/6044576627687424/4646958497005568> 
English 
<https://pg183.keap-link003.com/api/v1/click/6157898937139200/4646958497005568>
Spanish 
<https://pg183.keap-link003.com/api/v1/click/5245596612296704/4646958497005568> 
Portuguese 
<https://pg183.keap-link003.com/api/v1/click/5531052486819840/4646958497005568>
 <https://www.facebook.com/OTRSGroup/>  <https://twitter.com/otrsgroup>  
<https://www.linkedin.com/company/154779>  
<https://www.youtube.com/channel/UCHdOAyuwwkkk5ko_vy0X8_g>  
<https://www.instagram.com/otrs_group/>
Visit www.otrs.com 
<https://pg183.keap-link003.com/api/v1/click/4885809953374208/4646958497005568> 
or contact us.  
<https://pg183.keap-link003.com/api/v1/click/6045398979706880/4646958497005568>
OTRS AG

Zimmersmühlenweg 11
61440 Oberursel 
Germany
+49 6172 681988 0


Attachment: smime.p7s
Description: S/MIME cryptographic signature

--
_______________________________________________
announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
To manage your subscription or browse the message archive visit:
  https://lists.otrs.org/postorius/lists/announce.lists.otrs.org/

Reply via email to