Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-38060
HistoryJul 24, 2023 - 12:00 a.m.

CVE-2023-38060

2023-07-2400:00:00
ubuntu.com
ubuntu.com
10
cve-2023-38060
input validation
attachment
otrs
host header injection
authentication
vulnerability
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

24.3%

Improper Input Validation vulnerability in the ContentType parameter for
attachments on TicketCreate or TicketUpdate operations of the OTRS Generic
Interface modules allows any authenticated attacker to to perform an host
header injection for the ContentType header of the attachment. This issue
affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS))
Community Edition: from 6.0.1 through 6.0.34.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

24.3%