[Bug 1203131] New: VUL-0: CVE-2022-39050: otrs: Possible XSS stored in customer information
http://bugzilla.opensuse.org/show_bug.cgi?id=1203131 Bug ID: 1203131 Summary: VUL-0: CVE-2022-39050: otrs: Possible XSS stored in customer information Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/341496/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: chris@computersalat.de Reporter: thomas.leroy@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2022-39050 An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39050 https://www.cve.org/CVERecord?id=CVE-2022-39050 https://otrs.com/release-notes/otrs-security-advisory-2022-11/ -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203131 http://bugzilla.opensuse.org/show_bug.cgi?id=1203131#c1 --- Comment #1 from Thomas Leroy <thomas.leroy@suse.com> --- Should be affected: - openSUSE:Backports:SLE-15-SP4 = openSUSE:Backports:SLE-15-SP3 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203131 http://bugzilla.opensuse.org/show_bug.cgi?id=1203131#c2 Christian Wittmer <chris@computersalat.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |thomas.leroy@suse.com Resolution|--- |WONTFIX Flags| |needinfo?(thomas.leroy@suse | |.com) --- Comment #2 from Christian Wittmer <chris@computersalat.de> --- OTRS Community is EOL hence there won't be any fixes anymore. Kindly switch to OTOBO ( https://otobo.de/en/community/ ): http://download.opensuse.org/repositories/Application:/ITS:/otobo/ -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com