==================================================================== CERT-Renater Note d'Information No. 2018/VULN385 _____________________________________________________________________ DATE : 14/11/2018 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running OTRS versions prior to 6.0.14, 5.0.32, 4.0.33. ===================================================================== https://community.otrs.com/security-advisory-2018-10-security-update-for-otrs-framework/ https://community.otrs.com/security-advisory-2018-09-security-update-for-otrs-framework/ _____________________________________________________________________ Security Advisory 2018-10: Security Update for OTRS Framework November 14, 2018 — Please read carefully and check if the version of your OTRS system is affected by this vulnerability. Please send information regarding vulnerabilities in OTRS to: security@otrs.org PGP Key pub 2048R/9C227C6B 2011-03-21 [expires at: 2020-11-16] uid OTRS Security Team GPG Fingerprint E330 4608 DA6E 34B7 1551 C244 7F9E 44E9 9C22 7C6B Security Advisory Details ID: OSA-2018-10 Date: 2018-11-14 Title: Data loss during migration Severity: n/a Product: OTRS 6.0.x, OTRS 5.0.x Fixed in: OTRS 6.0.14, OTRS 5.0.32 URL: TBD FULL CVSS v3 VECTOR: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C References: n/a Vulnerability Description This advisory covers a problem with a data migration discovered in the OTRS framework. Privilege Escalation Users updating to OTRS 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table. Affected by this problem are OTRS 6.0.13 and OTRS 5.0.31 (earlier versions are not affected). This vulnerability is fixed in the latest versions of OTRS, and it is recommended to upgrade to the latest patch level. As a workaround after a performed migration, users can restore the user_preferences table from their backup and delete the OTRS cache via otrs/bin/otrs.Console.pl Maint::Delete::Cache. If the LDAP Sync module is used, it is sufficient to log in to the system again. Fixed releases can be found at: https://www.otrs.com/category/release-and-security-notes-en/ Detailed information about the changes: OTRS 6: https://github.com/OTRS/otrs/commit/8d17d58029efbb0bba25c4208e09e2d320eeb0c3 OTRS 5: https://github.com/OTRS/otrs/commit/7d3c56d5b9bb38207695dae174dbba89a132e7b9 However, to avoid unwanted side effects, we recommend a complete update. _____________________________________________________________________ Security Advisory 2018-09: Security Update for OTRS Framework November 09, 2018 — Please read carefully and check if the version of your OTRS system is affected by this vulnerability. Please send information regarding vulnerabilities in OTRS to: security@otrs.org PGP Key pub 2048R/9C227C6B 2011-03-21 [expires at: 2020-11-16] uid OTRS Security Team GPG Fingerprint E330 4608 DA6E 34B7 1551 C244 7F9E 44E9 9C22 7C6B Security Advisory Details ID: OSA-2018-09 Date: 2018-11-09 Title: Privilege Escalation Severity: 7.2 High Product: OTRS 5.0.x, OTRS 4.0.x Fixed in: OTRS 5.0.31, OTRS 4.0.33 FULL CVSS v3 VECTOR: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L/E:H/RL:O/RC:C References: TBD Vulnerability Description This advisory covers vulnerabilities discovered in the OTRS framework. Privilege Escalation An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. Affected by this vulnerability are all releases of OTRS 5.0.x up to and including 5.0.30, and OTRS 4.0.x up to and including 4.0.32. This vulnerability is fixed in the latest versions of OTRS, and it is recommended to upgrade to the latest patch level. Please note that to remove possibly affected records, the following clean-up SQL statements need to be executed: DELETE FROM user_preferences WHERE preferences_key = 'UserID' OR preferences_key = 'UserLogin' OR preferences_key = 'UserPw' OR preferences_key = 'UserFirstname' OR preferences_key = 'UserLastname' OR preferences_key = 'UserFullname' OR preferences_key = 'UserTitle' OR preferences_key = 'ChangeTime' OR preferences_key = 'CreateTime' OR preferences_key = 'ValidID' OR preferences_key LIKE 'UserIsGroup%'; DELETE FROM customer_preferences WHERE preferences_key = 'UserID' OR preferences_key = 'UserLogin' OR preferences_key = 'UserPassword' OR preferences_key = 'UserFirstname' OR preferences_key = 'UserLastname' OR preferences_key = 'UserFullname' OR preferences_key = 'UserStreet' OR preferences_key = 'UserCity' OR preferences_key = 'UserZip' OR preferences_key = 'UserCountry' OR preferences_key = 'UserComment' OR preferences_key = 'UserCustomerID' OR preferences_key = 'UserTitle' OR preferences_key = 'UserEmail' OR preferences_key = 'UserPhone' OR preferences_key = 'UserMobile' OR preferences_key = 'UserFax' OR preferences_key = 'UserMailString' OR preferences_key = 'ChangeTime' OR preferences_key = 'ChangeBy' OR preferences_key = 'CreateTime' OR preferences_key = 'CreateBy' OR preferences_key = 'ValidID' OR preferences_key LIKE 'UserIsGroup%'; Fixed releases can be found at: https://www.otrs.com/category/release-and-security-notes-en/ Detailed information about the changes: OTRS 5 https://github.com/OTRS/otrs/commit/7fad98052028505d3b40f3d51cf0ff1e40b24b94 OTRS 4 https://github.com/OTRS/otrs/commit/0829c24a9e7b78c5f2c51d8ebb1b39d5ba3f670e However, to avoid unwanted side effects, we recommend a complete update. Thanks to Francesco Sirocco for discovering and reporting this issue. Post navigation Previous post: Security Advisory 2018-08: Security Update for OTRS Framework ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================