When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.
2020-04-28T14:15:14.283
2024-11-21T05:11:21.797
Modified
CVSSv3.1: 4.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | otrs | otrs | ≤ 5.0.42 | Yes |
Application | otrs | otrs | ≤ 6.0.27 | Yes |
Application | otrs | otrs | ≤ 7.0.16 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |