First published: Mon Sep 06 2021(Updated: )
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.1 | |
Otrs Otrs | >=7.0.0<7.0.29 | |
Otrs Otrs | >=8.0.0<8.0.16 |
Update to OTRS 8.0.16 or OTRS 7.0.29.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-36096.
The severity of CVE-2021-36096 is medium with a severity value of 4.9.
CVE-2021-36096 affects OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions, OTRS 7.0.x version 7.0.28 and prior versions, and OTRS 8.0.x version 8.0.15 and prior versions.
To fix CVE-2021-36096, it is recommended to update OTRS AG Community Edition to version 6.0.1 or later, OTRS 7.x to version 7.0.29 or later, and OTRS 8.x to version 8.0.16 or later.
More information about CVE-2021-36096 can be found in the OTRS Security Advisory 2021-10 at https://otrs.com/release-notes/otrs-security-advisory-2021-10/.