CVE-2021-42137: Medium severity Zammad Zammad vulnerability
Published Oct 11, 2021
·Updated
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
Affected Software
1 affected component
Zammad Zammad<5.0.1
Event History
Oct 11, 2021
CVE Published
via MITRE·04:02 AM
Data Sourced
via MITRE·04:02 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue with Zammad?
The vulnerability ID for this issue with Zammad is CVE-2021-42137.
2
What is the severity of CVE-2021-42137?
The severity of CVE-2021-42137 is medium, with a CVSS score of 5.3.
3
How does CVE-2021-42137 affect Zammad?
CVE-2021-42137 affects Zammad versions up to and including 5.0.1.
4
What is the impact of CVE-2021-42137?
The impact of CVE-2021-42137 is improper enforcement of the privilege requirement for viewing a list of tickets in Zammad.
5
How can I fix CVE-2021-42137?
To fix CVE-2021-42137, upgrade to Zammad version 5.0.2 or later.