CVE-2021-44886
Last modified
CVE-2021-44886 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zammad | Zammad | 5.0.2 |
References
- https://zammad.com/en/advisories/zaa-2021-21Vendor Advisory
- https://zammad.com/en/advisories/zaa-2021-21Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44886?
How severe is CVE-2021-44886?
How do I fix CVE-2021-44886?
Are you affected by CVE-2021-44886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
