CVE-2023-50457: Medium severity zammad vulnerability
Published Dec 10, 2023
·Updated
An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge base answers of a ticket, a user could see entries for which they lack permissions.
Affected Software
3 affected components
Zammad Zammad=6.1.0
Zammad Zammad=6.1.0-alpha
Zammad Zammad=6.2.0-alpha
Event History
Dec 10, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50457?
CVE-2023-50457 has been classified with a significant severity level due to improper permission checks.
2
How do I fix CVE-2023-50457?
To mitigate CVE-2023-50457, upgrade to Zammad version 6.2.0 or later, where the issue has been resolved.
3
What systems are affected by CVE-2023-50457?
CVE-2023-50457 affects Zammad versions 6.1.0, 6.1.0-alpha, and 6.2.0-alpha.
4
What is the nature of the vulnerability in CVE-2023-50457?
CVE-2023-50457 allows unauthorized users to view knowledge base entries and tickets for which they do not have permissions.
5
Is there a workaround for CVE-2023-50457 if I cannot immediately upgrade?
There is no documented workaround for CVE-2023-50457; upgrading is the recommended course of action.