First published: Mon Aug 08 2022(Updated: )
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | =5.2.0 | |
Zammad Zammad | =5.2.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35488 is a vulnerability in Zammad 5.2.0 that allows an attacker to manipulate the rate limiting in the 'forgot password' feature, causing a Denial of Service (DoS) by sending many email requests to a known account.
CVE-2022-35488 affects Zammad version 5.2.0 and 5.2.0-alpha by allowing an attacker to abuse the rate limiting in the 'forgot password' feature and send multiple email requests, leading to a DoS condition.
CVE-2022-35488 has a severity rating of 7.5 (High).
To mitigate CVE-2022-35488, it is recommended to upgrade Zammad to a version where this vulnerability has been fixed, such as Zammad version 5.2.1 or later.
You can find more information about CVE-2022-35488 on the Zammad advisory page at https://zammad.com/de/advisories/zaa-2022-05.