Bugzilla – Bug 1068677
VUL-0: CVE-2017-15864: otrs: In the Agent Frontend a crafted URL allows to gain information like database user and password
Last modified: 2017-11-23 17:09:53 UTC
CVE-2017-15864 In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password. Also present in Factory, Leap versions References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15864 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15864 https://www.otrs.com/security-advisory-2017-06-security-update-otrs-3-3/
ongoing work ...
following projects updated to 3.3.19: - network:otrs:3_3 - OBS_Maintained:otrs
This is an autogenerated message for OBS integration: This bug (1068677) was mentioned in https://build.opensuse.org/request/show/542651 42.2+42.3 / otrs
done
openSUSE-SU-2017:3054-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1068677,1069391 CVE References: CVE-2017-15864,CVE-2017-16664 Sources used: openSUSE Leap 42.3 (src): otrs-3.3.20-14.1 openSUSE Leap 42.2 (src): otrs-3.3.20-5.11.1