CVE-2021-35299: High severity zammad vulnerability
Published Jun 28, 2021
·Updated
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
Affected Software
1 affected component
Zammad Zammad>=1.0.0<=4.0.0
Event History
Jun 28, 2021
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2021-35299.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.'
3
What is the severity of CVE-2021-35299?
The severity of CVE-2021-35299 is high with a severity value of 7.5.
4
How does CVE-2021-35299 impact Zammad?
CVE-2021-35299 allows attackers to obtain sensitive information through email connection configuration probing in Zammad 1.0.x up to 4.0.0.
5
Is there a fix available for CVE-2021-35299?
Yes, the fix for CVE-2021-35299 can be found in the advisory at https://zammad.com/en/advisories/zaa-2021-02.