CVE-2020-1770: Information disclosure in support bundle files
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRS Community Editionto a version that resolves this vulnerability.Fixed in 7.0.16 - Upgrade
Upgrade
OTRS Community Edition 6to a version that resolves this vulnerability.Fixed in 6.0.27 - Upgrade
Upgrade
OTRS Community Edition 5to a version that resolves this vulnerability.Fixed in 5.0.42
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-1770.
What is the severity of CVE-2020-1770?
CVE-2020-1770 has a severity rating of medium (4.3).
Which versions of ((OTRS)) Community Edition are affected by CVE-2020-1770?
CVE-2020-1770 affects ((OTRS)) Community Edition versions 5.0.41 and prior, 6.0.26 and prior.
Which versions of OTRS are affected by CVE-2020-1770?
CVE-2020-1770 affects OTRS versions 7.0.15 and prior.
How can I mitigate the vulnerability in ((OTRS)) Community Edition?
To mitigate the vulnerability in ((OTRS)) Community Edition, update to version 5.0.42 or 6.0.27.
How can I mitigate the vulnerability in OTRS?
To mitigate the vulnerability in OTRS, update to version 7.0.16.
What is the Common Weakness Enumeration (CWE) for CVE-2020-1770?
CVE-2020-1770 is associated with CWE-200 and CWE-201.