Description
Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zendesk
Zendesk zendesk |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:zendesk:zendesk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zendesk
Zendesk zendesk |
|
| Metrics |
cvssV3_1
|
Sat, 12 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-16T20:06:28.668Z
Reserved: 2024-10-12T00:00:00.000Z
Link: CVE-2024-49193
Updated: 2024-10-16T20:06:19.781Z
Status : Awaiting Analysis
Published: 2024-10-12T14:15:02.753
Modified: 2024-10-16T20:35:16.380
Link: CVE-2024-49193
No data.
OpenCVE Enrichment
No data.
Weaknesses