CVE-2020-10097: Medium severity zammad vulnerability
Published Mar 5, 2020
·Updated
An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=3.2.0
Remediation
Patch Available
Event History
Mar 5, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-10097.
2
What is the severity of CVE-2020-10097?
The severity of CVE-2020-10097 is medium with a CVSS score of 5.3.
3
What is the affected software?
The affected software is Zammad version 3.0 through 3.2.
4
How does CVE-2020-10097 impact the affected software?
CVE-2020-10097 may respond with verbose error messages that disclose internal application or infrastructure information, which could aid attackers in exploiting other vulnerabilities.
5
Is there a fix available for CVE-2020-10097?
Yes, a fix is available. Please refer to the security advisory from Zammad for more information on how to mitigate this vulnerability.