CVE Vulnerabilities

CVE-2025-32357

Authentication Bypass Using an Alternate Path or Channel

Published: Apr 05, 2025 | Modified: Apr 15, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Zammad Zammad 6.4.0 (including) 6.4.2 (excluding)

Potential Mitigations

References