PT-2023-32094 · Otrs+2 · Otrs+2

Matthias Terlinde

·

Publicado

2023-10-16

·

Atualizado

2024-08-06

·

CVE-2023-5422

CVSS v3.1

8.7

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 7.0.46 OTRS versions 8.0.X through 8.0.36 OTRS Community Edition versions 6.0.X through 6.0.34
Description The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL get verify result() function is not used, the certificate is trusted always, and it cannot be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.
Recommendations For OTRS versions 7.0.X through 7.0.46, update to version 7.0.47 or later. For OTRS versions 8.0.X through 8.0.36, update to version 8.0.37 or later. For OTRS Community Edition versions 6.0.X through 6.0.34, update to a version later than 6.0.34. As a temporary workaround, consider disabling the use of SSL/TLS for email communication until a patch is available. Restrict access to the email functionality to minimize the risk of exploitation. Avoid using the SSL get verify result() function until the issue is resolved.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-10583
CVE-2023-5422

Produtos afetados

Alt Linux
Otrs
Openssl