MGASA-2014-0194
Dashboard / Vulnerabilities / MGASA-2014-0194
Summary: Updated otrs packages fix multiple vulnerabilities
Details: Updated otrs package fixes security vulnerabilities: A logged in attacker could insert special content in dynamic fields, leading to JavaScript code being executed in OTRS (CVE-2014-2553). An attacker could embed OTRS in a hidden iframe tag of another page, tricking the user into clicking links in OTRS (CVE-2014-2554).
References: https://advisories.mageia.org/MGASA-2014-0194.html, https://www.otrs.com/security-advisory-2014-04-xss-issue/, https://www.otrs.com/security-advisory-2014-05-clickjacking-issue/, https://www.otrs.com/release-notes-otrs-help-desk-3-2-16/, http://lists.opensuse.org/opensuse-updates/2014-04/msg00062.html, https://bugs.mageia.org/show_bug.cgi?id=13252
Affected packages
Package
Name: otrs
Purl: pkg:rpm/mageia/otrs?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
