CVE-2024-49193: High severity zendesk vulnerability
Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49193?
CVE-2024-49193 is considered a critical vulnerability due to its potential for unauthorized access to sensitive ticket history.
How do I fix CVE-2024-49193?
To mitigate CVE-2024-49193, upgrade to Zendesk version 2024-07-02 or later, which addresses the vulnerability.
What types of attacks does CVE-2024-49193 allow?
CVE-2024-49193 enables remote attackers to read ticket history through e-mail spoofing.
Which versions of Zendesk are affected by CVE-2024-49193?
CVE-2024-49193 affects all Zendesk versions prior to 2024-07-02.
What is the mechanism exploited in CVE-2024-49193?
CVE-2024-49193 exploits insufficient checks in the Cc field extraction process from incoming e-mails to grant unauthorized ticket access.