First published: Mon Oct 17 2022(Updated: )
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
Credit: security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.0<=6.0.32 | |
Otrs Otrs | >=7.0.0<7.0.39 | |
Otrs Otrs | >=8.0.0<8.0.26 |
Update to OTRS 8.0.26 or OTRS 7.0.38.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39052.
The severity of CVE-2022-39052 is high with a score of 6.5.
The vulnerability allows an external attacker to send a specially crafted email with many recipients and trigger a potential DoS (Denial of Service) of the system.
The software versions affected by CVE-2022-39052 are OTRS 6.0.0 to 6.0.32, OTRS 7.0.0 to 7.0.39, and OTRS 8.0.0 to 8.0.26.
To fix the vulnerability CVE-2022-39052, update your OTRS software to a version that is not affected by the vulnerability. Refer to the OTRS Security Advisory (link provided) for more information.