CVE-2020-26031: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
Affected Software
1 affected component
Zammad Zammad>=1.0.0<3.4.1
Event History
Dec 28, 2020
CVE Published
via MITRE·07:57 AM
Data Sourced
via MITRE·07:57 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26031?
CVE-2020-26031 is an issue discovered in Zammad before 3.4.1, where the global-search feature leaks Knowledge Base drafts to Knowledge Base readers.
2
What is the severity of CVE-2020-26031?
The severity of CVE-2020-26031 is medium, with a severity value of 4.3.
3
How does CVE-2020-26031 affect Zammad?
CVE-2020-26031 affects Zammad versions before 3.4.1.
4
How can I fix CVE-2020-26031?
To fix CVE-2020-26031, you should update Zammad to version 3.4.1 or later.
5
Is there any additional information about CVE-2020-26031?
You can find more information about CVE-2020-26031 in the Zammad Security Advisory ZAA-2020-16: https://zammad.com/news/security-advisory-zaa-2020-16