First published: Mon Mar 21 2022(Updated: )
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Credit: security@otrs.com security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | <7.0.28 | |
Otrs Otrs | >=7.0.30<7.0.33 | |
Otrs Otrs | >=8.0.0<8.0.21 | |
Otrs Otrs Itsm | <7.0.19 | |
Otrs Otrs Itsm | >=8.0.0<8.0.28 | |
Otrs Otrs Storm | <8.0.12 |
Update to OTRS 8.0.20, OTRS 7.0.33. Update to OTRSSTORM 8.0.12, OTRS 7.0.28. Update to SystemMonitoring 8.0.9, OTRS 7.0.19.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36100 is a vulnerability in the OTRS system configuration that allows the execution of any system command.
CVE-2021-36100 affects OTRS versions 7.0.28 to 7.0.33 and versions 8.0.0 to 8.0.21, as well as OTRS ITSM versions 7.0.19 to 8.0.28 and OTRS Storm version 8.0.12.
CVE-2021-36100 has a severity rating of 8.8 (critical).
To fix CVE-2021-36100, OTRS users should update to the latest patched version of the software.
More information about CVE-2021-36100 can be found in the Debian LTS announce and the OTRS security advisory.