Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 621006 (CVE-2017-9324) - <www-apps/otrs-5.0.20: multiple vulnerabilities
Summary: <www-apps/otrs-5.0.20: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-9324
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 []
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-06 11:44 UTC by Thomas Deutschmann (RETIRED)
Modified: 2017-06-06 11:54 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-06 11:44:40 UTC
Vuln 1:
=======
Advisory: https://www.otrs.com/security-advisory-2017-02-security-update-otrs-versions/

Text:
-----
Certain pages of the OTRS interface are affected by a cross-site scripting vulnerability. It fails to sanitize user input to sufficiently remove HTML tags such as JavaScript from user input. A remote attacker can craft a malicious link containing JavaScript or other arbitrary HTML that will be executed in another user’s browser in the context of their OTRS session.

Affected by this vulnerability are all releases of OTRS 5.0.x up to and including 5.0.19, OTRS 4.0.x up to and including 4.0.23 and OTRS 3.3.x up to and including 3.3.16.


Vuln 2:
=======
CVE: CVE-2017-9324:

Advisory: https://www.otrs.com/security-advisory-2017-03-security-update-otrs-versions/

Text:
-----
An attacker with agent permission is capable by opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed.

Affected by this vulnerability are all releases of OTRS 5.0.x up to and including 5.0.19, OTRS 4.0.x up to and including 4.0.23 and OTRS 3.3.x up to and including 3.3.16.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-06 11:45:54 UTC
PR: https://github.com/gentoo/gentoo/pull/4869
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-06 11:54:54 UTC
Fixed via https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b78f42e46efa59a85dbd6e5f07679c7a38e99005

Repository is clean, all done.