CVE-2022-35488: High severity Zammad Zammad vulnerability
In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35488?
CVE-2022-35488 is a vulnerability in Zammad 5.2.0 that allows an attacker to manipulate the rate limiting in the 'forgot password' feature, causing a Denial of Service (DoS) by sending many email requests to a known account.
How does CVE-2022-35488 affect Zammad?
CVE-2022-35488 affects Zammad version 5.2.0 and 5.2.0-alpha by allowing an attacker to abuse the rate limiting in the 'forgot password' feature and send multiple email requests, leading to a DoS condition.
What is the severity of CVE-2022-35488?
CVE-2022-35488 has a severity rating of 7.5 (High).
How can I mitigate CVE-2022-35488?
To mitigate CVE-2022-35488, it is recommended to upgrade Zammad to a version where this vulnerability has been fixed, such as Zammad version 5.2.1 or later.
Where can I find more information about CVE-2022-35488?
You can find more information about CVE-2022-35488 on the Zammad advisory page at https://zammad.com/de/advisories/zaa-2022-05.