Back

MEDIUM

Information disclosure

Published Apr 28, 2020

Description

When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.

Affected products

Remediation

Vendor solution

Upgrade to OTRS 7.0.17, ((OTRS)) Community Edition 6.0.28 Patch for ((OTRS)) Community Edition 6: https://github.com/OTRS/otrs/commit/ff725cbea77f03fa296bb13f93f5b07086920342 Patch for ((OTRS)) Community Edition 5: https://github.com/OTRS/otrs/commit/fb0e6131e79aa2ba9c7acbd16f4ee4e73289f64b

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner OTRS
Published Apr 28, 2020
Updated Sep 16, 2024
Reserved Nov 29, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner OTRS
Published Apr 28, 2020
Updated Sep 16, 2024

GitHub

No data