This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40417 | A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jan 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Title | Missing X-Content-Type-Options: nosniff Header Allows MIME Type Sniffing | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2025-02-12T20:41:31.932Z
Reserved: 2024-08-13T13:38:47.973Z
Link: CVE-2024-43445
Updated: 2025-02-12T20:36:37.749Z
Status : Deferred
Published: 2025-01-27T06:15:23.743
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-43445
No data.
OpenCVE Enrichment
No data.
EUVD