CVE-2021-21440: Support Bundle includes S/Mime and PGP keys
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21440.
What is the severity of CVE-2021-21440?
The severity of CVE-2021-21440 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2021-21440?
The affected software versions are OTRS Community Edition 6.0.1 and later, OTRS 7.0.27 and prior, and OTRS 8.0.14 and prior.
How does CVE-2021-21440 affect OTRS AG ((OTRS)) Community Edition?
CVE-2021-21440 affects OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions.
How does CVE-2021-21440 affect OTRS AG OTRS?
CVE-2021-21440 affects OTRS AG OTRS 7.0.x version 7.0.27 and prior versions, and 8.0.x version 8.0.14 and prior versions.
What is the description of CVE-2021-21440?
CVE-2021-21440 is a vulnerability where generated Support Bundles contain private S/MIME and PGP keys if the containing folder is not hidden.
What is the fix for CVE-2021-21440?
To fix CVE-2021-21440, users should update to the latest version of OTRS AG OTRS Community Edition, OTRS 7, or OTRS 8, as applicable, as the vulnerability has been patched in newer versions.
Where can I find more information about CVE-2021-21440?
You can find more information about CVE-2021-21440 in the references provided: https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html and https://otrs.com/release-notes/otrs-security-advisory-2021-10/
Which Common Weakness Enumeration (CWE) ID is associated with CVE-2021-21440?
CVE-2021-21440 is associated with CWE-200.