CVE-2022-35487
NixOS vulnerability analysis and mitigation

Overview

Zammad 5.2.0 was discovered to contain an Incorrect Access Control vulnerability (CVE-2022-35487). The vulnerability stems from improper authorization checks on certain attachment endpoints, which could allow unauthenticated attackers to gain unauthorized access to attachments, including emails and attached files. The issue was discovered by Erik Kipka and Wilfried Kirsch from softScheck GmbH and was fixed in Zammad version 5.2.1 (Zammad Advisory).

Technical details

The vulnerability exists due to improper authorization validation on attachment endpoints in Zammad 5.2.0. The security flaw allows unauthorized access to the system's attachments, potentially exposing sensitive information stored in emails and attached files. The severity of this vulnerability is rated as high according to the vendor's security advisory (Zammad Advisory).

Impact

An unauthenticated attacker could exploit this vulnerability to gain unauthorized access to attachments stored in the Zammad system, including emails and attached files. This could lead to exposure of sensitive information stored in these attachments (Zammad Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Zammad version 5.2.1. Users are strongly recommended to upgrade to this version or later. Updates can be obtained from the official Zammad website (zammad.org), FTP server (ftp.zammad.com), or through the OS package manager (Zammad Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management