CVE-2025-32357: Medium severity zammad vulnerability
Published Apr 5, 2025
·Updated
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.
Affected Software
2 affected components
Zammad Zammad<6.4.2
Zammad Zammad>=6.4.0<6.4.2
Event History
Apr 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Dec 11, 57260
Event
via FIRST·03:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-32357?
CVE-2025-32357 is considered a medium severity vulnerability due to potential unauthorized access to knowledge base content.
2
How do I fix CVE-2025-32357?
To fix CVE-2025-32357, upgrade Zammad to version 6.4.2 or later.
3
Who is affected by CVE-2025-32357?
Authenticated agents with knowledge base permissions in Zammad versions prior to 6.4.2 are affected by CVE-2025-32357.
4
What type of vulnerability is CVE-2025-32357?
CVE-2025-32357 is an authenticated access control vulnerability.
5
What can attackers potentially do with CVE-2025-32357?
Attackers with valid agent credentials may exploit CVE-2025-32357 to access restricted knowledge base content.