CVE-2025-24389: SMTP Password will be shown in cleartext on some SMTP errors
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator.
This issue affects:
OTRS 7.0.X
OTRS 8.0.X OTRS 2023.X OTRS 2024.X
((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What are the affected versions for CVE-2025-24389?
The affected versions of OTRS include 7.0.X, 8.0.X, 2023.X, and 2024.X.
What is the impact of CVE-2025-24389?
CVE-2025-24389 could lead to sensitive information being logged and sent in emails to the system administrator.
How do I fix CVE-2025-24389?
To fix CVE-2025-24389, it is recommended to update to the latest patched version of OTRS provided by the vendor.
Is CVE-2025-24389 a significant risk?
Yes, CVE-2025-24389 is a significant risk due to the potential exposure of sensitive information.
What should I do if I am using an affected version of OTRS?
If you are using an affected version, you should apply the latest security updates and monitor logs for any unusual activity.