Vulnerability Description
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zammad | Zammad | < 3.5.1 |
References
- https://github.com/zammad/zammad/commit/f0462d4c20c2968b52b5dc6a585f26c0409b4fc4PatchThird Party Advisory
- https://zammad.com/en/advisories/zaa-2020-22Vendor Advisory
- https://github.com/zammad/zammad/commit/f0462d4c20c2968b52b5dc6a585f26c0409b4fc4PatchThird Party Advisory
- https://zammad.com/en/advisories/zaa-2020-22Vendor Advisory
FAQ
What is CVE-2020-29159?
CVE-2020-29159 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
How severe is CVE-2020-29159?
CVE-2020-29159 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29159?
Check the references section above for vendor advisories and patch information. Affected products include: Zammad Zammad.