Описание
Security update for otrs
This update for otrs to version 3.3.18 fixes the following issue:
This security issue was fixed:
- CVE-2017-14635: Remote authenticated users could have leveraged statistics-write permissions to gain privileges via code injection (bsc#1059691).
Список пакетов
openSUSE Leap 42.2
otrs-3.3.18-9.1
otrs-doc-3.3.18-9.1
otrs-itsm-3.3.14-9.1
openSUSE Leap 42.3
otrs-3.3.18-9.1
otrs-doc-3.3.18-9.1
otrs-itsm-3.3.14-9.1
Ссылки
- E-Mail link for openSUSE-SU-2017:2632-1
- SUSE Security Ratings
Описание
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Затронутые продукты
openSUSE Leap 42.2:otrs-3.3.18-9.1
openSUSE Leap 42.2:otrs-doc-3.3.18-9.1
openSUSE Leap 42.2:otrs-itsm-3.3.14-9.1
openSUSE Leap 42.3:otrs-3.3.18-9.1
Ссылки
- CVE-2017-14635
- SUSE Bug 1059691