CVE-2020-29159: Medium severity zammad vulnerability
Published Dec 28, 2020
·Updated
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
Affected Software
1 affected component
Zammad Zammad<3.5.1
Remediation
Event History
Dec 28, 2020
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
Description
Frequently Asked Questions
1
What is CVE-2020-29159?
CVE-2020-29159 is a vulnerability in Zammad before version 3.5.1.
2
What is the severity of CVE-2020-29159?
The severity of CVE-2020-29159 is medium with a severity value of 4.9.
3
How does CVE-2020-29159 affect Zammad?
CVE-2020-29159 affects Zammad versions before 3.5.1.
4
What is the impact of CVE-2020-29159?
CVE-2020-29159 allows the default signup Role in Zammad to be a privileged Role, if configured by an admin.
5
How can I fix CVE-2020-29159?
To fix CVE-2020-29159, upgrade Zammad to version 3.5.1 or later.