CVE-2021-42087: Medium severity Zammad Zammad vulnerability
Published Oct 7, 2021
·Updated
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
Affected Software
1 affected component
Zammad Zammad<4.1.1
Event History
Oct 7, 2021
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42087?
The severity of CVE-2021-42087 is medium, with a severity value of 4.9.
2
How does CVE-2021-42087 affect Zammad?
CVE-2021-42087 affects Zammad before version 4.1.1.
3
What is the issue in CVE-2021-42087?
In CVE-2021-42087, an admin can discover the application secret via the API in Zammad.
4
How can an admin exploit CVE-2021-42087?
An admin can exploit CVE-2021-42087 by using the API to discover the application secret.
5
How can CVE-2021-42087 be fixed?
CVE-2021-42087 can be fixed by updating Zammad to version 4.1.1 or later.