CVE Vulnerabilities

CVE-2021-44886

Published: Feb 04, 2022 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Zammad 5.0.2, agents can configure out of office periods and substitute persons. If the substitute persons didnt have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.

Affected Software

Name Vendor Start Version End Version
Zammad Zammad 5.0.2 (including) 5.0.2 (including)

References