PT-2025-5354 · Otrs+1 · Otrs+1

Published

2025-01-27

·

Updated

2025-01-27

·

CVE-2025-24389

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.X through 2024.X ((OTRS)) Community Edition version 6.0.x
Description Certain errors of the upstream libraries will insert sensitive information in the log mechanism and mails sent to the system administrator. Products based on the ((OTRS)) Community Edition are also very likely to be affected.
Recommendations For OTRS versions 7.0.X through 2024.X, consider restricting access to the log mechanism and system administrator mails until a patch is available. For ((OTRS)) Community Edition version 6.0.x, consider disabling the log mechanism temporarily to minimize the risk of sensitive information exposure. As a temporary workaround, consider implementing additional logging and monitoring measures to detect potential sensitive information leaks.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-24389

Affected Products

Otrs
Otrs Community Edition