otrs2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the otrs2 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2020-1774

<3.3.18-1+deb8u15
  • H
CVE-2020-1772

<3.3.18-1+deb8u15
  • H
Insufficient Entropy

*
  • M
CVE-2020-1769

*
  • M
Information Exposure

<3.3.18-1+deb8u15
  • M
CVE-2020-1767

<3.3.18-1+deb8u13
  • M
Improper Input Validation

<3.3.18-1+deb8u13
  • M
Cross-site Scripting (XSS)

<3.3.18-1+deb8u13
  • M
Information Exposure

<3.3.18-1+deb8u12
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

<3.3.18-1+deb8u11
  • M
CVE-2018-11563

<3.3.18-1+deb8u11
  • M
CVE-2019-13458

<3.3.18-1+deb8u11
  • M
CVE-2019-12248

<3.3.18-1+deb8u10
  • M
Information Exposure

<3.3.18-1+deb8u10
  • M
XML Injection

<3.3.18-1+deb8u9
  • M
Cross-site Scripting (XSS)

<3.3.18-1+deb8u14
  • M
Arbitrary Code Injection

<3.3.18-1+deb8u8
  • M
Direct Request ('Forced Browsing')

<3.3.18-1+deb8u7
  • M
Cross-site Scripting (XSS)

<3.3.18-1+deb8u7
  • M
Improper Input Validation

<3.3.18-1+deb8u6
  • M
CVE-2018-16586

<3.3.18-1+deb8u6
  • H
CVE-2018-14593

<3.3.18-1+deb8u5
  • H
SQL Injection

<3.2.9-1
  • M
Improper Privilege Management

<3.1.7+dfsg1-8
  • M
Information Exposure

<3.2.8-1
  • M
Information Exposure

<3.2.7-1
  • H
Unrestricted Upload of File with Dangerous Type

*
  • H
Information Exposure

<3.3.18-1+deb8u4
  • M
Information Exposure

<3.3.18-1+deb8u3
  • H
OS Command Injection

<3.3.18-1+deb8u3
  • H
Arbitrary Code Injection

<3.3.18-1+deb8u2
  • H
CVE-2017-15864

<3.3.18-1+deb8u2
  • H
Improper Input Validation

<3.3.18-1+deb8u1
  • H
Improper Privilege Management

<3.3.9-3+deb8u1
  • M
Cross-site Scripting (XSS)

<3.3.18-1+deb8u1
  • M
Access Restriction Bypass

<3.3.9-3
  • M
Improper Input Validation

<3.3.6-1
  • L
Cross-site Scripting (XSS)

<3.3.6-1
  • M
Cross-site Scripting (XSS)

<3.3.5-1
  • H
SQL Injection

<3.3.4-1
  • M
Cross-site Request Forgery (CSRF)

<3.3.4-1
  • M
Cross-site Scripting (XSS)

<3.1.7+dfsg1-6
  • L
Cross-site Scripting (XSS)

<3.1.7+dfsg1-5
  • M
Cross-site Scripting (XSS)

<3.1.7+dfsg1-4
  • M
CVE-2011-2746

<2.4.7-1
  • M
Cross-site Scripting (XSS)

<2.4.10+dfsg1-1
  • M
Access Restriction Bypass

<2.3.2-1
  • M
Improper Input Validation

<2.4.5-1
  • M
Credentials Management

<2.4.10+dfsg1-1
  • M
Improper Input Validation

<2.4.7+dfsg1-1
  • M
Access Restriction Bypass

<2.3.2-1
  • L
Cryptographic Issues

<3.0.8+dfsg1-1
  • M
Improper Input Validation

<2.3.2-1
  • M
Information Exposure

<2.2.7-1
  • M
Access Restriction Bypass

<2.3.2-1
  • M
Cryptographic Issues

<2.4.5-1
  • L
Improper Input Validation

<2.4.5-1
  • M
Cryptographic Issues

<3.0.8+dfsg1-1
  • L
Access Restriction Bypass

<2.4.5-1
  • M
Access Restriction Bypass

<3.0.8+dfsg1-1
  • M
Access Restriction Bypass

<2.4.5-1
  • M
Access Restriction Bypass

<2.2.6-1
  • M
Improper Input Validation

<2.2.7-1
  • L
Information Exposure

<3.0.8+dfsg1-1
  • M
Access Restriction Bypass

<3.0.8+dfsg1-1
  • L
Cross-site Scripting (XSS)

<3.0.8+dfsg1-1
  • M
Cross-site Scripting (XSS)

<2.3.3-1
  • M
Race Condition

<2.4.8+dfsg1-1
  • M
Improper Input Validation

<3.0.8+dfsg1-1
  • M
Access Restriction Bypass

<2.2.6-1
  • H
OS Command Injection

<2.4.5-1
  • L
Cross-site Scripting (XSS)

<2.4.9+dfsg1-1
  • M
Improper Input Validation

<2.4.8+dfsg1-1
  • L
Cross-site Scripting (XSS)

<2.4.8+dfsg1-1
  • M
SQL Injection

<2.4.7-1
  • H
CVE-2008-7220

<2.3.4-6
  • M
Access Restriction Bypass

<2.2.5-2
  • M
Cross-site Scripting (XSS)

<2.1.1-1