In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31687 | In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://zammad.com/en/advisories/zaa-2021-21 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:32:12.957Z
Reserved: 2021-12-13T00:00:00
Link: CVE-2021-44886
No data.
Status : Modified
Published: 2022-02-04T15:15:12.793
Modified: 2024-11-21T06:31:39.757
Link: CVE-2021-44886
No data.
OpenCVE Enrichment
No data.
EUVD