PT-2022-25553 · Zammad · Zammad

Published

2022-09-27

·

Updated

2023-08-08

·

CVE-2022-40816

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad version 5.2.1
Description The issue concerns Incorrect Access Control in Zammad's asset handling mechanism. This mechanism is designed to prevent customer users from accessing personal information of other users. However, the logic was ineffective when used through a web socket connection, allowing a logged-in attacker to fetch personal data of other users by querying the Zammad API.
Recommendations For Zammad version 5.2.1, update to version 5.2.2 to resolve the issue. As a temporary workaround, consider restricting access to the Zammad API to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-40816

Affected Products

Zammad