Описание
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| znuny | not-affected | package | ||
| otrs2 | fixed | 6.3.2-1 | package | |
| otrs2 | no-dsa | bullseye | package |
Примечания
https://www.znuny.org/en/releases/znuny-6-3-2
https://www.znuny.org/en/advisories/zsa-2022-02
https://github.com/znuny/Znuny/commit/309ec536540201a5b2741314e928c54a792bb845 (rel-6_0_41)
https://github.com/znuny/Znuny/commit/f6fe8ca2e48a18680ace94df0d84eb1e2c26e685 (rel-6_0_41)
https://github.com/znuny/Znuny/commit/42458dad68f330e3f94294348de29e48cc9432c8 (rel-6_0_41)
https://github.com/znuny/Znuny/commit/02ac202c624bfccfd97e7f4ea95e0fd4adcf7a07 (rel-6_0_41)
EPSS
Связанные уязвимости
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Specially crafted string in OTRS system configuration can allow the execution of any system command.
EPSS