PT-2023-32094 · Otrs+2 · Otrs+2

Matthias Terlinde

·

Published

2023-10-16

·

Updated

2024-08-06

·

CVE-2023-5422

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 7.0.46 OTRS versions 8.0.X through 8.0.36 OTRS Community Edition versions 6.0.X through 6.0.34
Description The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL get verify result() function is not used, the certificate is trusted always, and it cannot be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.
Recommendations For OTRS versions 7.0.X through 7.0.46, update to version 7.0.47 or later. For OTRS versions 8.0.X through 8.0.36, update to version 8.0.37 or later. For OTRS Community Edition versions 6.0.X through 6.0.34, update to a version later than 6.0.34. As a temporary workaround, consider disabling the use of SSL/TLS for email communication until a patch is available. Restrict access to the email functionality to minimize the risk of exploitation. Avoid using the SSL get verify result() function until the issue is resolved.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10583
CVE-2023-5422

Affected Products

Alt Linux
Otrs
Openssl