Hostname and Certificate Validation Flaw in Zammad by Zammad GmbH
CVE-2023-50454

5.9MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
10 December 2023

What is CVE-2023-50454?

An issue was discovered in Zammad prior to version 6.2.0, where SSL/TLS connections to external services were established without sufficient validation of hostnames and certificate authorities. This lack of proper validation allows potential man-in-the-middle attackers to exploit the connection, leading to unauthorized access to sensitive data. It is crucial for users to update to the latest version to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.