CVE-2022-35489

Source
https://cve.org/CVERecord?id=CVE-2022-35489
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-35489.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-35489
Published
2022-08-08T14:15:10.853Z
Modified
2026-02-13T00:41:17.740418Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.

References

Affected packages

Git / github.com/zammad/zammad

Affected ranges

Type
GIT
Repo
https://github.com/zammad/zammad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*
1.6.0
1.6.1
2.*
2.10.0
3.*
3.7.0
5.*
5.2.0
5.2.0-alpha

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-35489.json"