
Cloud Vulnerability DB
A community-led vulnerabilities database
A WebSocket server Denial of Service (DoS) vulnerability was discovered in Zammad versions 1.0.x up to 3.2.0, identified as CVE-2020-10101. The vulnerability was disclosed on March 3, 2020, and affects the WebSocket server component of the Zammad helpdesk system (Zammad Advisory).
The vulnerability occurs when messages in non-JSON format are sent to Zammad's WebSocket server. The root cause is improper message format validation and unhandled parsing errors, which can lead to a crash of the service process (Zammad Advisory).
When successfully exploited, this vulnerability can cause a Denial of Service condition by crashing the WebSocket server service process (Zammad Advisory).
The vulnerability has been fixed in Zammad versions 3.2.1 and 3.3.0. Users are recommended to upgrade to these or later versions. Updates can be obtained through the official Zammad website, FTP server, or through the OS package manager (Zammad Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."