CVE-2020-14213: Medium severity zammad vulnerability
Published Jun 16, 2020
·Updated
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
Affected Software
1 affected component
Zammad Zammad<3.3.1
Remediation
Event History
Jun 16, 2020
CVE Published
via MITRE·10:22 PM
Data Sourced
via MITRE·10:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14213.
2
What is the severity of CVE-2020-14213?
The severity of CVE-2020-14213 is medium with a CVSS score of 5.4.
3
How can a Customer access ticket information that should only be available to an Agent?
In Zammad before 3.3.1, a vulnerability allows Customers to access ticket information that should only be available to Agents, such as reading internal data, splitting, or merging.
4
What software versions are affected by CVE-2020-14213?
Zammad versions up to, but excluding, 3.3.1 are affected by CVE-2020-14213.
5
Is there a fix available for CVE-2020-14213?
Yes, upgrading to Zammad version 3.3.1 or later will fix CVE-2020-14213.