Untriaged
Zammad is missing authorization in ticket create endpoint
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for ticket creation was missing authorization if the related parameter for adding links is used. This vulnerability is fixed in 7.0.1 and 6.5.4.
References
-
https://github.com/zammad/zammad/security/advisories/GHSA-28m3-wwgv-ppw8 x_refsource_CONFIRM
Affected products
zammad
- ==< 6.5.4
- ==>= 7.0.0-alpha, < 7.0.1
Matching in nixpkgs
pkgs.zammad
Zammad, a web-based, open source user support/ticketing solution
pkgs.python312Packages.zammad-py
Python API client for accessing zammad REST API
pkgs.python313Packages.zammad-py
Python API client for accessing zammad REST API
pkgs.python314Packages.zammad-py
Python API client for accessing zammad REST API
Package maintainers
-
@Radvendii Taeer Bar-Yam <taeer@necsi.edu>
-
@NetaliDev Jennifer Graul <me@netali.de>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>