it-securitynotifies AT lists.piratenpartei.de
Betreff:
Sicherheitsankündigungen
Listenarchiv
- From: Bernd Maus <bernd.maus AT otrs.com>
- To: announce AT otrs.org
- Subject: [IT-SecNots] [announce]New Security Updates for OTRS
- Date: Mon, 20 Mar 2023 09:17:32 +0100
- Archived-at: <https://lists.otrs.org/hyperkitty/list/announce AT lists.otrs.org/message/36QZGIF3YTXFIH4GHPQZL2IXU6CBQRAO/>
- Authentication-results: mail.piratenpartei.de; dkim=pass header.d=otrs.com header.s=otrs1 header.b=fG19veIl; spf=none (mail.piratenpartei.de: domain of announce-bounces AT lists.otrs.org has no SPF policy when checking 135.181.4.15) smtp.mailfrom=announce-bounces AT lists.otrs.org; dmarc=none
- List-archive: <https://lists.otrs.org/hyperkitty/list/announce AT lists.otrs.org/>
- List-id: "Announcements about OTRS.org" <announce.lists.otrs.org>
Dear reader, The following security fix/es was/were made: |
|
OTRS Security Advisory 2023-01 - ID: OSA-2023-01
- Date: 2023-03-20
- Title: Possible XSS in Ticket Actions
- Severity: 5.4 MEDIUM
- Product: OTRS 7.0.x
- Fixed in: OTRS 7.0.42
- FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- References: CVE-2023-1248
OTRS Security Advisory 2023-02 - ID: OSA-2023-02
- Date: 2023-03-20
- Title: Code execution through ACL creation
- Severity: 7.4 HIGH
- Product: OTRS 7.0.x, OTRS 8.0.x
- Fixed in: OTRS 7.0.42, OTRS 8.0.31
- FULL CVSS v3.1 VECTOR: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
- References: CVE-2023-1250
|
|
Kind regards, Your OTRS release team |
|
Subscribe to the OTRS Newsletter.Read about OTRS service management solutions, product features, and interesting tips from our experts every month. Simply select your desired language.
|
|
OTRS AG Zimmersmühlenweg 11 61440 Oberursel Germany +49 6172 681988 0 |
|
--
_______________________________________________
announce mailing list -- announce AT lists.otrs.org
To unsubscribe send an email to announce-leave AT lists.otrs.org
To manage your subscription or browse the message archive visit:
https://lists.otrs.org/postorius/lists/announce.lists.otrs.org/
-
[IT-SecNots] [announce]New Security Updates for OTRS,
Bernd Maus, 20.03.2023
Archiv bereitgestellt durch MHonArc 2.6.24.