CVE-2021-36096: Support Bundle includes S/Mime and PGP secret or PIN
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-36096.
What is the severity of CVE-2021-36096?
The severity of CVE-2021-36096 is medium with a severity value of 4.9.
Which software versions are affected by CVE-2021-36096?
CVE-2021-36096 affects OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions, OTRS 7.0.x version 7.0.28 and prior versions, and OTRS 8.0.x version 8.0.15 and prior versions.
How can I fix CVE-2021-36096?
To fix CVE-2021-36096, it is recommended to update OTRS AG Community Edition to version 6.0.1 or later, OTRS 7.x to version 7.0.29 or later, and OTRS 8.x to version 8.0.16 or later.
Where can I find more information about CVE-2021-36096?
More information about CVE-2021-36096 can be found in the OTRS Security Advisory 2021-10 at https://otrs.com/release-notes/otrs-security-advisory-2021-10/.