CVE-2020-10096: Infoleak
An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a user's workstation can browse the browser cache contents and obtain sensitive information. The attacker does not need to be authenticated with the application to view this information, as it would be available via the browser cache.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10096?
CVE-2020-10096 is classified as a medium-severity vulnerability due to its potential for disclosing confidential data.
How do I fix CVE-2020-10096?
To mitigate CVE-2020-10096, ensure you upgrade Zammad to version 3.3.0 or later, which addresses this caching issue.
What type of data is exposed in CVE-2020-10096?
CVE-2020-10096 can expose sensitive information that is cached within the browser memory.
Who is affected by CVE-2020-10096?
Users of Zammad versions 3.0 through 3.2 are affected by CVE-2020-10096.
What attack vectors are possible with CVE-2020-10096?
An attacker can exploit CVE-2020-10096 by accessing a compromised system remotely or through physical access to retrieve cached sensitive information.