PT-2021-14507 · Otrs Ag+1 · Otrs+1

László Gyaraki

·

Published

2021-02-08

·

Updated

2024-08-06

·

CVE-2021-21435

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTRS AG OTRS versions 7.0.x through 7.0.23 OTRS AG OTRS versions 8.0.x through 8.0.10
Description The issue concerns the exposure of Article Bcc fields and agent personal information when a customer prints a ticket in PDF format via an external interface.
Recommendations For versions 7.0.x through 7.0.23, update to a version newer than 7.0.23 to resolve the issue. For versions 8.0.x through 8.0.10, update to a version newer than 8.0.10 to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2917
ALT-PU-2021-3039
ALT-PU-2021-3058
ALT-PU-2024-10583
CVE-2021-21435

Affected Products

Alt Linux
Otrs