Input validation error in OTRS - CVE-2018-16587
Published: September 28, 2018 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
Affected software
otrs (Alpine package)
Opensuse
SUSE Linux
How to mitigate CVE-2018-16587
otrs (Alpine package) - update to 6.0.33-r0
External References
- https://community.otrs.com/security-advisory-2018-04-security-update-for-otrs-framework/
- https://github.com/OTRS/otrs/commit/a4a1a01f84fac7ab032570ee50b660e2ebb15c01
- https://github.com/OTRS/otrs/commit/d8cae00b0f78c2a07bb10cedb817304139395843
- https://github.com/OTRS/otrs/commit/d9db0c6a15caafda7689320ecf61777993c33711
- https://lists.debian.org/debian-lts-announce/2018/09/msg00033.html
- https://www.debian.org/security/2018/dsa-4317