CVE-2024-43445: Otrs AG Otrs

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

Affected products

  • Otrs AG Otrs: from 7.0, before 7.1 (fixed in 7.1); from 8.0, before 8.1 (fixed in 8.1); from 2023, before 2024 (fixed in 2024); from 2024, before 2025 (fixed in 2025); from 2025, before 2025.2 (fixed in 2025.2)
  • Otrs AG Otrs Community Edition: from 6.0, up to and including 6.0.34

Published 2025-01-27. Last modified 2026-06-17.