An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
References
| Link | Resource |
|---|---|
| https://zammad.com/de/advisories/zaa-2022-02 | Patch Vendor Advisory |
Configurations
Information
Published : 2022-04-26 20:15
Updated : 2022-05-05 12:34
NVD link : CVE-2022-27331
Mitre link : CVE-2022-27331
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
zammad
- zammad


