CVE-2023-6254: Password is send back to client
Published Nov 27, 2023
·Updated
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.
Affected Software
1 affected component
OTRS OTRS>=8.0.1<=8.0.37
Remediation
Information
Update to OTRS Patch 2023.1.1
Event History
Nov 27, 2023
CVE Published
09:44 AM
Data Sourced
09:44 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-6254.
2
What is the severity of CVE-2023-6254?
The severity of CVE-2023-6254 is high (8.1).
3
Which software versions are affected by CVE-2023-6254?
CVE-2023-6254 affects OTRS versions 8.0.X through 8.0.37.
4
What is the impact of CVE-2023-6254?
CVE-2023-6254 allows the reading of plain text passwords, which are sent back to the client in the server response.
5
How can I fix CVE-2023-6254?
To fix CVE-2023-6254, update OTRS to version 8.0.38 or later.