An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
References
| Link | Resource |
|---|---|
| https://zammad.com/de/advisories/zaa-2022-02 | Patch Vendor Advisory |
| https://zammad.com/de/advisories/zaa-2022-02 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2022-04-27 03:15
Updated : 2024-11-21 06:55
NVD link : CVE-2022-27331
Mitre link : CVE-2022-27331
CVE.ORG link : CVE-2022-27331
JSON object : View
Products Affected
zammad
- zammad
CWE
CWE-668
Exposure of Resource to Wrong Sphere
