CVE Vulnerabilities

CVE-2022-39051

Improper Control of Dynamically-Managed Code Resources

Published: Sep 05, 2022 | Modified: Oct 01, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

Name Vendor Start Version End Version
Otrs Otrs 6.0.0 (including) 6.0.32 (including)
Otrs Otrs 7.0.0 (including) 7.0.37 (excluding)
Otrs Otrs 8.0.0 (including) 8.0.25 (excluding)
Znuny Ubuntu kinetic *
Znuny Ubuntu lunar *
Znuny Ubuntu mantic *
Znuny Ubuntu trusty *
Znuny Ubuntu xenial *

Potential Mitigations

References