Zum Inhalt springen

Zammad Release Notes

4 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Zammad, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Zammad

Zammad 7.2.1: Sicherheitslücken geschlossen

Zammad 7.2.1 behebt mehrere Sicherheitslücken, darunter Umgehung der Multi-Faktor-Authentifizierung, Remote Code Execution über die Automations-Konfiguration und mehrere Stored-XSS-Probleme, wobei SaaS-Instanzen bereits gepatcht sind und Self-Hosted-Installationen umgehend aktualisieren sollten.

Recommended Resolution

SaaS Customers: No action is required. Your instances have already been patched and secured by our team.

Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.

Vulnerabilities patched

For full technical details, please refer to the security advisories on GitHub.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Zammad

Zammad 7.2: Manipulationssicheres Admin-Audit-Log

Zammad 7.2 führt ein Audit-Log für administrative Aktionen ein, das Änderungen im Admin-Bereich manipulationssicher aufzeichnet und weder über die Oberfläche noch per API bearbeitet oder gelöscht werden kann.

Want to see the new features in action? Join our release webinar or let Marcel—aka “That Helpdesk Guy”—walk you through the highlights in his latest video on YouTube.

Join the Release Webinar Watch YT Video

1. Security & Compliance

🛡️ Tamper-Proof Admin Audit Log

Who changed which setting, and when? Especially in larger Zammad environments, having a clear answer to this question isn't just helpful for troubleshooting—it's vital for IT security, internal controls, and external audits.

With version 7.2, we are introducing an audit log for administrative actions. Changes made in the admin area are recorded in a tamper-proof way and can be fully traced. As with the ticket history, these entries cannot be edited or deleted — either through the user interface or via the API.

The audit log is much more than just a record of administrative changes. It provides a reliable basis for demonstrating accountability and control processes to auditors. Along with Zammad's ISO/IEC 27001:2022 certification and SOC 2 Type I, it establishes an even stronger foundation for security and compliance. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Zammad

Zammad 7.1.3: Sicherheitslücken geschlossen

Zammad 7.1.3 behebt mehrere Sicherheitslücken, darunter eine SSRF-Umgehung per DNS Rebinding, die Offenlegung von Objekten über den Core-Workflow-Endpunkt und mandantenübergreifende Anhangsoffenlegung, wobei SaaS-Instanzen bereits gepatcht sind und Self-Hosted-Installationen umgehend aktualisieren sollten.

Recommended Resolution

SaaS Customers: No action is required. Your instances have already been patched and secured by our team.

Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.

Vulnerabilities patched

For full technical details, please refer to the security advisories on GitHub.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Zammad

Zammad 7.1.2: Sicherheitslücken geschlossen

Zammad 7.1.2 behebt mehrere Sicherheitslücken, darunter Remote Code Execution über den AI-Agent-Template-Sanitizer, gefälschte S/MIME- und PGP-Signaturprüfungen sowie fehlende Autorisierungsprüfungen, wobei SaaS-Instanzen bereits gepatcht sind und Self-Hosted-Installationen umgehend aktualisieren sollten.

Recommended Resolution

SaaS Customers: No action is required. Your instances have already been patched and secured by our team.

Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.

Vulnerabilities patched

For full technical details, please refer to the security advisories on GitHub.

Originalquelle(öffnet in neuem Tab)Problem melden