PT-2024-2035 · Otrs+1 · Otrs+1

Published

2024-01-29

·

Updated

2024-02-02

·

CVE-2024-23791

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 7.0.48 OTRS versions 8.0.X through 8.0.37 OTRS versions 2023.X through 2023.1.1
Description The issue is related to the insertion of debug information into a log file during the building of an Elasticsearch index, which allows the reading of sensitive information from articles. This can be exploited by a remote attacker to disclose protected information.
Recommendations For OTRS versions 7.0.X through 7.0.48, update to a version outside of this range to resolve the issue. For OTRS versions 8.0.X through 8.0.37, update to a version outside of this range to resolve the issue. For OTRS versions 2023.X through 2023.1.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-01913
CVE-2024-23791

Affected Products

Elasticsearch
Otrs