Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-35488: Security Advisory ZAA-2022-05 | Zammad

In Zammad 5.2.0, an attacker could manipulate the rate limiting in the ‘forgot password’ feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

CVE
#vulnerability#dos

Security Advisory

5. Juli 2022 · Please read carefully and check if the version of your Zammad system is affected by this vulnerability. Please send us information regarding vulnerabilities in Zammad!

Security Advisory Details

  • ID: ZAA-2022-05
  • Date: 07/05/2022
  • Title: Denial Of Service
  • Severity: low
  • Product: Zammad 5.2.x
  • Fixed in: Zammad 5.2.1
  • References:
    –> pending CVE assignment

Vulnerability Descriptions****Denial Of Service

An attacker could manipulate the rate limiting in the ‘forgot password’ feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

Special 🙏 and 🤘 and ❤️ to:

  • N: Joe Helle
  • W: https://themayor.tech/

Recommended Resolution

This vulnerability is fixed in the latest versions of Zammad and it is recommended to upgrade to one of these.

Fixed releases can be found at:

  • https://zammad.org/
  • https://ftp.zammad.com/

Or just update your Zammad if installed via OS package manager.

Additional information

Online version of this advisory: https://zammad.com/en/advisories/zaa-2022-05

Send all remarks on security issues to [email protected].

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907