CVE-2020-26029: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:57 AM
Data Sourced
via MITRE·07:57 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-26029.
2
What is the severity of CVE-2020-26029?
The severity of CVE-2020-26029 is medium with a severity value of 6.5.
3
How does CVE-2020-26029 impact Zammad?
CVE-2020-26029 impacts Zammad by allowing wrong authorization checks for impersonation requests via X-On-Behalf-Of.
4
Is there a fix available for CVE-2020-26029?
Yes, a fix is available for CVE-2020-26029 in Zammad version 3.4.1.
5
Where can I find more information about CVE-2020-26029?
More information about CVE-2020-26029 can be found in the security advisory on the Zammad website at https://zammad.com/news/security-advisory-zaa-2020-20.