In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2025-04 | Vendor Advisory |
Configurations
History
15 Apr 2025, 16:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://zammad.com/en/advisories/zaa-2025-04 - Vendor Advisory | |
First Time |
Zammad
Zammad zammad |
|
CWE | CWE-306 | |
CPE | cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:* |
07 Apr 2025, 14:17
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
05 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-05 21:15
Updated : 2025-04-15 16:37
NVD link : CVE-2025-32357
Mitre link : CVE-2025-32357
CVE.ORG link : CVE-2025-32357
JSON object : View
Products Affected
zammad
- zammad