First published: Mon Aug 08 2022(Updated: )
In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zammad Zammad | =5.2.0 | |
Zammad Zammad | =5.2.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35489 is a vulnerability in Zammad 5.2.0 that allows customers with secondary organizations assigned to see all organizations of the system instead of only those they are assigned to.
CVE-2022-35489 allows customers with secondary organizations assigned to view all organizations in the system, which can lead to unauthorized access and privacy breaches.
CVE-2022-35489 has a severity level of medium, with a severity value of 6.5.
To fix CVE-2022-35489, it is recommended to upgrade to a version of Zammad that is not affected by this vulnerability.
For more information about CVE-2022-35489, you can refer to the advisory on the Zammad website: https://zammad.com/de/advisories/zaa-2022-06