
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Zammad before version 3.5.1 (CVE-2020-29159), identified on December 28, 2020. The vulnerability allows the default signup Role for newly created Users to be configured as a privileged Role by an administrator, which was an unintended behavior (NVD, Zammad Advisory).
The vulnerability has a CVSS v3.1 Base Score of 4.9 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. The issue stems from a design flaw where administrators could assign privileged roles as default roles for new user signups, potentially granting excessive permissions to newly created accounts (NVD).
The vulnerability could lead to potential information disclosure by allowing newly created users to access restricted parts of Zammad if an administrator has configured privileged roles as default signup roles (Zammad Advisory).
The vulnerability requires an administrator to explicitly configure privileged roles as default signup roles. While the severity is rated as medium, exploitation requires administrative access to misconfigure the system (NVD).
The issue has been fixed in Zammad version 3.5.1 and later. The fix includes restricting the permissions that can be used for default signup roles to a specific set of non-privileged permissions, such as user preferences and basic customer ticket access. Organizations should upgrade to version 3.5.1 or later to address this vulnerability (Zammad Advisory, GitHub Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."