First published: Mon Jul 26 2021(Updated: )
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.
Credit: security@otrs.com security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<=6.0.1 | |
Otrs Otrs | >=7.0.0<=7.0.27 | |
Otrs Otrs | >=8.0.0<=8.0.14 |
Update to OTRS 8.0.15 or OTRS 7.0.28.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21440.
The severity of CVE-2021-21440 is medium with a CVSS score of 6.5.
The affected software versions are OTRS Community Edition 6.0.1 and later, OTRS 7.0.27 and prior, and OTRS 8.0.14 and prior.
CVE-2021-21440 affects OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions.
CVE-2021-21440 affects OTRS AG OTRS 7.0.x version 7.0.27 and prior versions, and 8.0.x version 8.0.14 and prior versions.
CVE-2021-21440 is a vulnerability where generated Support Bundles contain private S/MIME and PGP keys if the containing folder is not hidden.
To fix CVE-2021-21440, users should update to the latest version of OTRS AG OTRS Community Edition, OTRS 7, or OTRS 8, as applicable, as the vulnerability has been patched in newer versions.
You can find more information about CVE-2021-21440 in the references provided: https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html and https://otrs.com/release-notes/otrs-security-advisory-2021-10/
CVE-2021-21440 is associated with CWE-200.