CVE-2020-29158: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
Affected Software
1 affected component
Zammad Zammad<3.5.1
Remediation
Event History
Dec 28, 2020
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-29158.
2
What is the severity of CVE-2020-29158?
The severity of CVE-2020-29158 is medium, with a severity value of 4.3.
3
What is the affected software?
The affected software is Zammad before version 3.5.1.
4
What is the impact of CVE-2020-29158?
CVE-2020-29158 allows an Agent with Customer permissions to bypass access control on internal Articles via the Ticket detail view.
5
How can I fix CVE-2020-29158?
To fix CVE-2020-29158, upgrade to Zammad version 3.5.1 or later.