CVE-2023-50453: Medium severity zammad vulnerability
Published Dec 10, 2023
·Updated
An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
Affected Software
3 affected components
Zammad Zammad=6.1.0
Zammad Zammad=6.1.0-alpha
Zammad Zammad=6.2.0-alpha
Event History
Dec 10, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50453?
CVE-2023-50453 is classified as a medium severity vulnerability due to the exposure of internal configuration data.
2
How do I fix CVE-2023-50453?
To fix CVE-2023-50453, upgrade Zammad to version 6.2.0 or later.
3
What impact does CVE-2023-50453 have on user data?
CVE-2023-50453 allows unauthorized users to view internal user object attributes, potentially exposing sensitive configuration information.
4
Which versions of Zammad are affected by CVE-2023-50453?
CVE-2023-50453 affects Zammad versions 6.1.0 and 6.1.0-alpha.
5
Is there a workaround for CVE-2023-50453 before upgrading?
There is no known workaround for CVE-2023-50453; upgrading to a patched version is necessary.