CVE-2020-10101: Input Validation
Published Mar 5, 2020
·Updated
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors not handled. This leads to a crash of the service process.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=3.2.0
Remediation
Patch Available
Event History
Mar 5, 2020
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10101?
CVE-2020-10101 has a severity rating classified as high due to the potential for service disruption.
2
How do I fix CVE-2020-10101?
To fix CVE-2020-10101, update Zammad to the latest version beyond 3.2.0 where the vulnerability has been addressed.
3
What systems are affected by CVE-2020-10101?
CVE-2020-10101 affects Zammad versions from 3.0 to 3.2 inclusive.
4
What kind of attack does CVE-2020-10101 facilitate?
CVE-2020-10101 facilitates a denial of service attack by causing the WebSocket server to crash.
5
Is there a way to mitigate CVE-2020-10101 without updating?
There are no reliable mitigations for CVE-2020-10101 without updating to a secure version.