CVE-2023-50454: Medium severity zammad vulnerability
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50454?
CVE-2023-50454 is considered to be a high severity vulnerability due to its exploitability by man-in-the-middle attackers.
How do I fix CVE-2023-50454?
To fix CVE-2023-50454, upgrade to Zammad version 6.2.0 or later, which includes proper hostname and certificate authority validation.
What systems are affected by CVE-2023-50454?
CVE-2023-50454 affects Zammad versions 6.1.0 and 6.1.0-alpha, as well as 6.2.0-alpha.
Can CVE-2023-50454 lead to data breaches?
Yes, CVE-2023-50454 can potentially lead to data breaches if attackers exploit the vulnerability to intercept sensitive information.
What type of attacks can exploit CVE-2023-50454?
CVE-2023-50454 can be exploited through man-in-the-middle attacks due to the lack of proper validation in SSL/TLS connections.