Information on source package otrs2

Available versions

ReleaseVersion
jessie3.3.18-1+deb8u15
stretch/non-free5.0.16-1+deb9u6
buster/non-free6.0.16-2+deb10u1
bullseye/non-free6.0.32-6

Open issues

BugjessiestretchbusterbullseyeDescription
CVE-2023-38060vulnerablevulnerablefixedvulnerable (no DSA)Improper Input Validation vulnerability in the ContentType parameter f ...
CVE-2022-4427vulnerablevulnerablefixedvulnerable (no DSA)Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTR ...
CVE-2021-41184vulnerablevulnerable (no DSA)fixedvulnerable (no DSA)jQuery-UI is the official jQuery user interface library. Prior to vers ...
CVE-2021-41183vulnerablevulnerable (no DSA)fixedvulnerable (no DSA)jQuery-UI is the official jQuery user interface library. Prior to vers ...
CVE-2021-41182vulnerablevulnerable (no DSA)fixedvulnerable (no DSA)jQuery-UI is the official jQuery user interface library. Prior to vers ...
CVE-2021-36100vulnerablevulnerablefixedvulnerable (no DSA)Specially crafted string in OTRS system configuration can allow the ex ...
CVE-2021-36096vulnerableunknownunknownunknownGenerated Support Bundles contains private S/MIME and PGP keys if cont ...
CVE-2021-36094vulnerableunknownunknownunknownIt's possible to craft a request for appointment edit screen, which co ...
CVE-2021-36092vulnerableunknownunknownunknownIt's possible to create an email which contains specially crafted link ...
CVE-2021-36091vulnerablevulnerable (no DSA)fixedfixedAgents are able to list appointments in the calendars without required ...
CVE-2021-21443vulnerablevulnerable (no DSA)fixedfixedAgents are able to list customer user emails without required permissi ...
CVE-2021-21441vulnerablevulnerable (no DSA)fixedfixedThere is a XSS vulnerability in the ticket overview screens. It's poss ...
CVE-2021-21440vulnerablevulnerable (no DSA)fixedfixedGenerated Support Bundles contains private S/MIME and PGP keys if cont ...
CVE-2021-21439vulnerablevulnerable (no DSA)fixedfixedDoS attack can be performed when an email contains specially designed ...
CVE-2021-21435vulnerablefixedfixedfixedArticle Bcc fields and agent personal information are shown when custo ...
CVE-2021-21252vulnerablevulnerable (no DSA, ignored)fixedfixedThe jQuery Validation Plugin provides drop-in validation for your exis ...
CVE-2020-11023vulnerablevulnerable (no DSA, ignored)fixedfixedIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, pa ...
CVE-2020-11022vulnerablevulnerable (no DSA, ignored)fixedfixedIn jQuery versions greater than or equal to 1.2 and before 3.5.0, pass ...
CVE-2020-1776vulnerablevulnerable (no DSA, ignored)fixedfixedWhen an agent user is renamed or set to invalid the session belonging ...
CVE-2020-1774fixedvulnerable (no DSA, ignored)fixedfixedWhen user downloads PGP or S/MIME keys/certificates, exported file has ...
CVE-2020-1773vulnerable (no DSA)vulnerable (no DSA, ignored)fixedfixedAn attacker with the ability to generate session IDs or password reset ...
CVE-2020-1772fixedvulnerable (no DSA, ignored)fixedfixedIt's possible to craft Lost Password requests with wildcards in the To ...
CVE-2020-1771fixedvulnerable (no DSA, ignored)fixedfixedAttacker is able craft an article with a link to the customer address ...
CVE-2020-1770fixedvulnerable (no DSA, ignored)fixedfixedSupport bundle generated files could contain sensitive information tha ...
CVE-2020-1769vulnerable (no DSA)vulnerable (no DSA, ignored)fixedfixedIn the login screens (in agent and customer interface), Username and P ...
CVE-2020-1767fixedvulnerable (no DSA, ignored)fixedfixedAgent A is able to save a draft (i.e. for customer reply). Then Agent ...
CVE-2020-1766fixedvulnerable (no DSA, ignored)fixedfixedDue to improper handling of uploaded images it is possible in very unl ...
CVE-2020-1765fixedvulnerable (no DSA, ignored)fixedfixedAn improper control of parameters allows the spoofing of the from fiel ...
CVE-2019-18180fixedvulnerable (no DSA, ignored)fixedfixedImproper Check for filenames with overly long extensions in PostMaster ...
CVE-2019-18179fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-16375vulnerable (no DSA)vulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-13458fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-12746fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) Community ...
CVE-2019-12497fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-12248fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-11358fixedvulnerable (no DSA, ignored)fixedfixedjQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other produc ...
CVE-2019-10067fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 7.x throu ...
CVE-2019-9892fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 5.x throu ...
CVE-2019-9752fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 5.x befor ...
CVE-2019-9751fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 6.x befor ...
CVE-2018-20800fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 5.0.31 an ...
CVE-2018-19143fixedvulnerable (no DSA, ignored)fixedfixedOpen Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5. ...
CVE-2018-19141fixedvulnerable (no DSA, ignored)fixedfixedOpen Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before ...
CVE-2018-11563fixedvulnerable (no DSA, ignored)fixedfixedAn issue was discovered in Open Ticket Request System (OTRS) 6.0.x thr ...

Open unimportant issues

BugjessiestretchbusterbullseyeDescription
CVE-2018-7567vulnerablevulnerablevulnerablevulnerableIn the Admin Package Manager in Open Ticket Request System (OTRS) 5.0. ...

Resolved issues

BugDescription
CVE-2020-1778When OTRS uses multiple backends for user authentication (with LDAP), ...
CVE-2020-1777Agent names that participates in a chat conversation are revealed in c ...
CVE-2020-1775BCC recipients in mails sent from OTRS are visible in article detail o ...
CVE-2020-1768The external frontend system uses numerous background calls to the bac ...
CVE-2019-13457An issue was discovered in Open Ticket Request System (OTRS) 7.0.x thr ...
CVE-2019-10066An issue was discovered in Open Ticket Request System (OTRS) 7.x throu ...
CVE-2019-10065An issue was discovered in Open Ticket Request System (OTRS) 7.0 throu ...
CVE-2019-9753An issue was discovered in Open Ticket Request System (OTRS) 7.x befor ...
CVE-2018-19142Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin ...
CVE-2018-17883An issue was discovered in Open Ticket Request System (OTRS) 6.0.x bef ...
CVE-2018-16587In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before ...
CVE-2018-16586In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before ...
CVE-2018-14593An issue was discovered in Open Ticket Request System (OTRS) 6.0.x thr ...
CVE-2018-10198An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is ...
CVE-2017-17476Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5. ...
CVE-2017-16921In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and includin ...
CVE-2017-16854In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, ...
CVE-2017-16664Code injection exists in Kernel/System/Spelling.pm in Open Ticket Requ ...
CVE-2017-15864In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x throu ...
CVE-2017-14635In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4 ...
CVE-2017-9324In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through ...
CVE-2016-9139Cross-site scripting (XSS) vulnerability in Open Ticket Request System ...
CVE-2014-9324The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x befo ...
CVE-2014-2554OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 ...
CVE-2014-2553Cross-site scripting (XSS) vulnerability in Open Ticket Request System ...
CVE-2014-1695Cross-site scripting (XSS) vulnerability in Open Ticket Request System ...
CVE-2014-1694Multiple cross-site request forgery (CSRF) vulnerabilities in (1) Cust ...
CVE-2014-1471SQL injection vulnerability in the StateGetStatesByType function in Ke ...
CVE-2013-4717Multiple SQL injection vulnerabilities in Open Ticket Request System ( ...
CVE-2013-4088Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OT ...
CVE-2013-3551Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS ...
CVE-2013-2625An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, ...
CVE-2012-4751Cross-site scripting (XSS) vulnerability in Open Ticket Request System ...
CVE-2012-4600Cross-site scripting (XSS) vulnerability in Open Ticket Request System ...
CVE-2012-2582Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Req ...
CVE-2011-2746Unspecified vulnerability in Kernel/Modules/AdminPackageManager.pm in ...
CVE-2011-2385The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in ...
CVE-2011-1518Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Req ...
CVE-2011-1433The (1) AgentInterface and (2) CustomerInterface components in Open Ti ...
CVE-2011-0456webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier al ...
CVE-2010-4768Open Ticket Request System (OTRS) before 2.3.5 does not properly disab ...
CVE-2010-4767Open Ticket Request System (OTRS) before 2.3.6 does not properly handl ...
CVE-2010-4766The AgentTicketForward feature in Open Ticket Request System (OTRS) be ...
CVE-2010-4765Race condition in the Kernel::System::Main::FileWrite method in Open T ...
CVE-2010-4764Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, ...
CVE-2010-4763The ACL-customer-status Ticket Type setting in Open Ticket Request Sys ...
CVE-2010-4762Cross-site scripting (XSS) vulnerability in the rich-text-editor compo ...
CVE-2010-4761The customer-interface ticket-print dialog in Open Ticket Request Syst ...
CVE-2010-4760Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notifi ...
CVE-2010-4759Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly ...
CVE-2010-4758installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an ...
CVE-2010-4071Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2. ...
CVE-2010-3476Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before ...
CVE-2010-2080Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Req ...
CVE-2010-0438Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in O ...
CVE-2009-5057The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 d ...
CVE-2009-5056Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly ...
CVE-2009-5055Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on ...
CVE-2008-7283Open Ticket Request System (OTRS) before 2.2.6, when customer group su ...
CVE-2008-7282Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open T ...
CVE-2008-7281Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing ...
CVE-2008-7280Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Reque ...
CVE-2008-7279The CustomerInterface component in Open Ticket Request System (OTRS) b ...
CVE-2008-7278The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, ...
CVE-2008-7277Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw ...
CVE-2008-7276Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) befo ...
CVE-2008-7275Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Req ...
CVE-2008-7220Unspecified vulnerability in Prototype JavaScript framework (prototype ...
CVE-2008-1515The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 a ...
CVE-2007-2524Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Re ...
CVE-2007-2383The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data ...

Security announcements

DSA / DLADescription
DLA-3551-1otrs2 - security update
DLA-2198-1otrs2 - security update
DLA-2118-1otrs2 - security update
DLA-2079-1otrs2 - security update
DLA-2053-1otrs2 - security update
DLA-1877-1otrs2 - security update
DLA-1816-1otrs2 - security update
DLA-1774-1otrs2 - security update
DLA-1721-1otrs2 - security update
DLA-1592-1otrs2 - security update
DSA-4317-1otrs2 - security update
DLA-1521-1otrs2 - security update
DLA-1473-1otrs2 - security update
DSA-4069-1otrs2 - security update
DLA-1215-1otrs2 - security update
DLA-1212-1otrs2 - security update
DSA-4066-1otrs2 - security update
DSA-4047-1otrs2 - security update
DSA-4021-1otrs2 - security update
DLA-1119-1otrs2 - security update
DSA-3876-1otrs2 - security update
DLA-787-1otrs2 - security update
DSA-3124-1otrs2 - security update
DSA-2867-1otrs2 - several
DSA-2733-1otrs2 - SQL injection
DSA-2712-1otrs2 - privilege escalation
DSA-2696-1otrs2 - privilege escalation
DSA-2536-1otrs2 - cross-site scripting
DSA-2231-1otrs2 - cross-site scripting
DSA-1993-1otrs2 - SQL injection
DSA-1298-1otrs2

Search for package or bug name: Reporting problems