Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Zammad 7.2.1: Sicherheitslücken geschlossen
Zammad 7.2.1 behebt mehrere Sicherheitslücken, darunter Umgehung der Multi-Faktor-Authentifizierung, Remote Code Execution über die Automations-Konfiguration und mehrere Stored-XSS-Probleme, wobei SaaS-Instanzen bereits gepatcht sind und Self-Hosted-Installationen umgehend aktualisieren sollten.
Recommended Resolution
SaaS Customers: No action is required. Your instances have already been patched and secured by our team.
Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.
Vulnerabilities patched
For full technical details, please refer to the security advisories on GitHub.
- Unfiltered sign-up and ticket update fields allow cross-organization ticket disclosure and takeover
- Multi-factor authentication could be bypassed through the email verification flow
- Remote code execution via template sanitizer bypass in automation configuration
- Stored XSS in desktop autocomplete fields via unescaped option label
- Stored XSS in ticket zoom via attacker-controlled article preferences
- Arbitrary configuration disclosure via recent view endpoint …