When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore its possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 5.0.0 (including) | 5.0.42 (including) |
Otrs | Otrs | 6.0.0 (including) | 6.0.27 (including) |
Otrs | Otrs | 7.0.0 (including) | 7.0.16 (including) |
Otrs2 | Ubuntu | bionic | * |
Otrs2 | Ubuntu | eoan | * |
Otrs2 | Ubuntu | trusty | * |
Otrs2 | Ubuntu | xenial | * |