Bug 1188740 - (CVE-2021-36092) VUL-1: CVE-2021-36092: otrs: It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack
(CVE-2021-36092)
VUL-1: CVE-2021-36092: otrs: It's possible to create an email which contains ...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Wolfgang Engel
Security Team bot
https://smash.suse.de/issue/305166/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-07-27 10:49 UTC by Robert Frohl
Modified: 2021-07-27 11:15 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-07-27 10:49:51 UTC
CVE-2021-36092

It's possible to create an email which contains specially crafted link and it
can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS))
Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x
version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-36092
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36092
http://www.cvedetails.com/cve/CVE-2021-36092/
https://otrs.com/release-notes/otrs-security-advisory-2021-15/
Comment 1 Robert Frohl 2021-07-27 10:50:01 UTC
relevant for Leap