PT-2023-22455 · Zammad · Zammad

Published

2023-05-02

·

Updated

2025-01-30

·

CVE-2023-29867

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad versions 5.3.x through 5.3.x
Description The issue allows an authenticated attacker to gain information about linked accounts of users involved in their tickets using the Zammad API. This is due to Incorrect Access Control.
Recommendations For Zammad versions 5.3.x, update to version 5.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the Zammad API until the update is applied.

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2023-29867

Affected Products

Zammad