CVE Vulnerabilities

CVE-2023-29867

Published: May 02, 2023 | Modified: May 10, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.

Affected Software

Name Vendor Start Version End Version
Zammad Zammad 5.3.0 (including) 5.4.0 (excluding)

References