• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

NEWS | November 25, 2022

OTOBO and Spooky SSL

The currently used MariaDB version in OTOBO’s standard configuration is not affected by the OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786.

Many software projects are affected by the 2022 OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786, also known as Spooky SSL. We’re taking this opportunity to describe the current state in OTOBO.

Docker Environments

In the current standard configuration, OTOBO uses MariaDB version 10.5 as its database. The standard database can be changed via the OTOBO_IMAGE_DB setting in docker_compose.

The MariaDB 10.5 image is based on Ubuntu Focal, which is the 20.04 LTS version that will receive regular security updates until April 2025.

Ubuntu Focal uses OpenSSL version 1.1.1, which is not vulnerable according to Canonical / Ubuntu / focal (20.04 LTS).
The Image Vulnerability Database notes that vulnerability arises from dependencies:

“Based on information currently available, the following products – through their usage or dependency to OpenSSL 3.x – will be vulnerable:

Debian 12 (bookworm) and unstable
Ubuntu 22.04 and 22.10
RedHat Enterprise Linux 9
Alpine 3.15, 3.16 and edge
Node.js 18 and 19”

Therefore, the MariaDB version we currently use as standard is not vulnerable to the OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786.

We still recommend that all users check if they are running the current version of the image.

OTOBO without Docker

If you’re using OTOBO without Docker, it’s essential to install a current distribution that receives regular security updates.
Make sure to install these automatically or at least regularly.
The major distributions have quickly fixed the OpenSSL vulnerability and provided corresponding updates.
To check if your installed MariaDB version uses a vulnerable version of the library, you can use the ‘ldd’ command:

$ ldd /usr/bin/mariadb | grep ssl
In the output, you’ll see that version 1.1 of the libssl library is used, which is not affected by this vulnerability:
libssl.so.1.1 => /lib/x86_64-linux-gnu/libssl.so.1.1 (0x00007fb8b53d00)
On Debian and Ubuntu, you can use the ‘dpkg’ command to display the currently installed version of the package:

$ dpkg -s libssl1.1 | grep Version
The output also indicates a non-vulnerable version:
Version: 1.1.1f-1ubuntu2.13

In general, we recommend migrating to the Docker variant in the medium term, as it promises more operational security among other benefits. We’ll be happy to support you in this process.

If you have any questions, feel free to contact our support.

Download OTOBO

About Rother OSS GmbH

The Rother OSS GmbH is the owner of the source code for the open-source service management platform OTOBO. We support our customers with consulting, development, support, and managed services during the introduction and operation of OTOBO. With OTOBO, organizations can design their processes more efficiently, increase employee productivity, and improve service quality – in IT, customer, or enterprise service management. At the same time, they retain control over their data, reduce risks, and save costs. We are passionate about open-source software and believe in the benefits of cooperative development. By releasing OTOBO under the GNU General Public License (GPL v3.0), we want to share our enthusiasm for the open-source model with users, particularly a flexible, scalable, and extendable service management platform. Together with customers, partners, developers, and users, we form the OTOBO community. Nothing motivates us more than enabling additional organizations to use OTOBO to delight their customers with exceptional service. Every smile counts – every day. While we have been offering services for the precursor of OTOBO, the helpdesk system OTRS, since 2011, the community has had a better alternative available since 2019: OTOBO, which is 100% open-source and remains so. Find the latest news about OTOBO at otobo.io or LinkedIn. Follow us!

Press contact

Grit Rother
Tel: +49 9427 68 39 000

Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OTOBO 10.1.10 Link to: OTOBO 10.1.10 OTOBO 10.1.10OTOBO Security Patch Link to: Effectively Managing Services with an Integrated CMDB Link to: Effectively Managing Services with an Integrated CMDB Effectively Managing Services with an Integrated CMDBEffectively Managing Services with an Integrated CMDB
Scroll to top Scroll to top Scroll to top