Candidate: CVE-2020-1774 PublicDate: 2020-04-28 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1774 https://otrs.com/release-notes/otrs-security-advisory-2020-11/ Description: When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N [4.9 MEDIUM] Patches_otrs2: upstream_otrs2: needs-triage precise/esm_otrs2: DNE trusty_otrs2: ignored (out of standard support) trusty/esm_otrs2: DNE xenial_otrs2: ignored (end of standard support, was needs-triage) bionic_otrs2: needs-triage eoan_otrs2: ignored (reached end-of-life) focal_otrs2: needs-triage groovy_otrs2: not-affected (6.0.28-1) hirsute_otrs2: not-affected (6.0.28-1) impish_otrs2: not-affected (6.0.28-1) jammy_otrs2: not-affected (6.0.28-1) devel_otrs2: not-affected (6.0.28-1)