CVE-2022-35490: Critical severity Zammad Zammad vulnerability
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35490?
CVE-2022-35490 is a vulnerability in Zammad 5.2.0 that allows for privilege escalation.
How severe is CVE-2022-35490?
CVE-2022-35490 has a severity rating of critical (9.8).
What software versions are affected by CVE-2022-35490?
Zammad versions 5.2.0 and 5.2.0-alpha are affected by CVE-2022-35490.
Is there a prevention against brute-force attacks in Zammad?
Zammad has a prevention against brute-force attacks that is designed to invalidate users and prevent logins after a configurable number of attempts.
How can an attacker work around the brute-force prevention in Zammad and exploit CVE-2022-35490?
An attacker could potentially bypass the prevention measures in Zammad, allowing them to send more requests and potentially escalate privileges.