HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-5422

CVSS 8.7v3.1pub. 2023-10-16upd. 2024-11-21

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
  • Otrs

    APP
    Otrs
    6.0.0 – 6.0.347.0.0 – 7.0.47 (excl.)8.0.0 – 8.0.37 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-48188CRITICAL9.1PL ✓same product

OTRS / Community Edition: SQL injection z pominięciem uwierzytelnienia

CVE-2026-48209HIGH7.1same product

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling al...

CVE-2023-6254HIGH8.1same product

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which ...

CVE-2023-38056HIGH7.2same product

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTas...

CVE-2023-2534HIGH7.6same product

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticat...