First published: Mon Feb 08 2021(Updated: )
Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<=6.0.30 | |
Otrs Otrs | >=7.0.0<=7.0.23 | |
Otrs Otrs | >=8.0.0<=8.0.10 |
Update to OTRS 8.0.11 or OTRS 7.0.24.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21435.
The severity of CVE-2021-21435 is medium (severity value: 6.5).
OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions are affected by CVE-2021-21435.
CVE-2021-21435 allows Bcc fields and agent personal information to be shown when a customer prints the ticket (PDF) via the external interface.
You can find more information about CVE-2021-21435 in the OTRS Security Advisory 2021-02: [OTRS Security Advisory 2021-02](https://otrs.com/release-notes/otrs-security-advisory-2021-02/).