Hostname and Certificate Validation Flaw in Zammad by Zammad GmbH
CVE-2023-50454
5.9MEDIUM
What is CVE-2023-50454?
An issue was discovered in Zammad prior to version 6.2.0, where SSL/TLS connections to external services were established without sufficient validation of hostnames and certificate authorities. This lack of proper validation allows potential man-in-the-middle attackers to exploit the connection, leading to unauthorized access to sensitive data. It is crucial for users to update to the latest version to mitigate the risks associated with this vulnerability.
