CVE-2022-40817: Medium severity Zammad Zammad vulnerability
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in 5.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 5.2.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-40817.
What is the affected software?
The affected software is Zammad 5.2.1.
What is the severity of CVE-2022-40817?
The severity of CVE-2022-40817 is medium with a severity value of 4.3.
What operations were agents wrongly able to perform on tickets with read-only access?
Agents were wrongly able to perform operations such as adding and removing links, tags, and related answers on tickets with read-only access.
How was the issue fixed?
The issue was fixed in Zammad 5.2.2.