Znuny Security Advisory for OTRS - ZSA-2012-01

Moderator: crythias

Locked
mikeeduard
Znuny newbie
Posts: 10
Joined: 19 Aug 2012, 09:43
Znuny Version: 3.1.x
Real Name: Mike Eduard
Company: Znuny GmbH

Znuny Security Advisory for OTRS - ZSA-2012-01

Post by mikeeduard »

There is a public known OTRS Vulnerability for OTRS 3.1, OTRS 3.0 and OTRS 2.4.

Problem
An attacker could trick a logged in user to execute malicious java script code by sending a prepared email into OTRS.

Affected by this vulnerability are all releases of OTRS 2.4.x up to and including 2.4.12, OTRS 3.0.x up to and including 3.0.14, as well as all 3.1.x versions up to and including 3.1.8.

Workaround
As workaround you need to disable the rich text feature via sys config.

Fix
If you are looking for a fix, just go here:

http://znuny.com/en/#!/advisory/ZSA-2012-01

Details
  • ZSA-2012-01
  • Date: 2012-08-17
  • Title: Several XSS attacks possible
  • Severity: Critical
  • Product: OTRS 3.1.x, OTRS 3.0.x, OTRS 2.4.x
  • Fixed in: Only by installing the addon package Znuny4OTRS-CVE-2012-2582
  • URL: http://znuny.com/en/#!/advisory/ZSA-2012-01
  • CVE 2012-2582
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: Znuny Security Advisory for OTRS - ZSA-2012-01

Post by jojo »

"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
mikeeduard
Znuny newbie
Posts: 10
Joined: 19 Aug 2012, 09:43
Znuny Version: 3.1.x
Real Name: Mike Eduard
Company: Znuny GmbH

Re: Znuny Security Advisory for OTRS - ZSA-2012-01

Post by mikeeduard »

JFI, the package from http://znuny.com/en/#!/advisory/ZSA-2012-01 will also work with ITSM and other extensions. The CVS Files will brake other functionality.
jojo
Znuny guru
Posts: 15020
Joined: 26 Jan 2007, 14:50
Znuny Version: Git Master
Contact:

Re: Znuny Security Advisory for OTRS - ZSA-2012-01

Post by jojo »

For ITSM you need to use the versions from the ITSM CVS
"Production": OTRS™ 8, OTRS™ 7, STORM powered by OTRS
"Testing": ((OTRS Community Edition)) and git Master

Never change Defaults.pm! :: Blog
Professional Services:: http://www.otrs.com :: enjoy@otrs.com
mikeeduard
Znuny newbie
Posts: 10
Joined: 19 Aug 2012, 09:43
Znuny Version: 3.1.x
Real Name: Mike Eduard
Company: Znuny GmbH

Re: Znuny Security Advisory for OTRS - ZSA-2012-01

Post by mikeeduard »

Exactly, with the Znuny package you do not need to take care! Just install it and it's done. No mater if ITSM, a custom extention or plain OTRS. :)
Locked