CVE Vulnerabilities

CVE-2022-35488

Published: Aug 08, 2022 | Modified: Aug 08, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the forgot password feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

Affected Software

Name Vendor Start Version End Version
Zammad Zammad 5.2.0 (including) 5.2.0 (including)
Zammad Zammad 5.2.0-alpha (including) 5.2.0-alpha (including)

References