This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches. Optional: Use MTA based sending on the OTRS instance e.g. postfix
Vendor Workaround
Use a local MTA for sending instead of SMTP configuration within OTRS
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3685 | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected |
Mon, 27 Jan 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Title | SMTP Password will be shown in cleartext on some SMTP errors | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2025-02-12T20:41:31.676Z
Reserved: 2025-01-21T09:09:58.721Z
Link: CVE-2025-24389
No data.
Status : Deferred
Published: 2025-01-27T06:15:24.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24389
No data.
OpenCVE Enrichment
No data.
EUVD