CVE-2023-38059: Infoleak
The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38059.
What is the severity of CVE-2023-38059?
The severity of CVE-2023-38059 is medium with a CVSS score of 5.3.
How does CVE-2023-38059 affect OTRS?
CVE-2023-38059 affects OTRS versions 6.0.X through 6.0.34, 7.0.X through 7.0.47, and 8.0.X through 8.0.37.
What is the impact of CVE-2023-38059?
CVE-2023-38059 allows an attacker to bypass the blocking of external images, potentially leading to the retrieval of user IP addresses.
Is there a fix available for CVE-2023-38059?
Yes, a fix is available for CVE-2023-38059. It is recommended to update to OTRS versions 6.0.35, 7.0.48, or 8.0.38 or later.