First published: Mon Sep 05 2022(Updated: )
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<=6.0.32 | |
Otrs Otrs | >=7.0.0<7.0.37 | |
Otrs Otrs | >=8.0.0<8.0.25 |
Update to OTRS 8.0.25 or OTRS 7.0.37.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-39051.
The severity of CVE-2022-39051 is high with a severity value of 8.8.
The affected software for CVE-2022-39051 are OTRS versions 6.0.0 to 6.0.32, 7.0.0 to 7.0.37, and 8.0.0 to 8.0.25.
An attacker can exploit CVE-2022-39051 by having the admin install an unverified 3rd party package in the Template toolkit.
Yes, you can find more information about CVE-2022-39051 in the OTRS security advisory: https://otrs.com/release-notes/otrs-security-advisory-2022-12/