CVE-2020-1774: Information disclosure
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-1774?
CVE-2020-1774 is a vulnerability that affects ((OTRS)) Community Edition versions 5.0.42 and prior, and 6.0.27 and prior. It allows for the mixing of private and public keys when downloading PGP or S/MIME keys/certificates.
What is the severity of CVE-2020-1774?
CVE-2020-1774 has a severity rating of 4.9 (medium).
How does CVE-2020-1774 affect ((OTRS)) Community Edition?
CVE-2020-1774 affects ((OTRS)) Community Edition versions 5.0.42 and prior, and 6.0.27 and prior. It allows for the mixing of private and public keys when downloading PGP or S/MIME keys/certificates.
How can I fix CVE-2020-1774?
To fix CVE-2020-1774, upgrade to a version of ((OTRS)) Community Edition that is not affected by this vulnerability.
Where can I find more information about CVE-2020-1774?
More information about CVE-2020-1774 can be found in the following references: [Reference 1](https://lists.debian.org/debian-lts-announce/2020/05/msg00000.html), [Reference 2](https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html), [Reference 3](https://otrs.com/release-notes/otrs-security-advisory-2020-11/).