CVE Vulnerabilities

CVE-2023-29867

Published: May 02, 2023 | Modified: Jan 30, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

Affected Software

NameVendorStart VersionEnd Version
ZammadZammad5.3.0 (including)5.4.0 (excluding)

References