Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wgm-v99f-436j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.

EPSS

Процентиль: 65%
0.00494
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.

CVSS3: 9.8
debian
около 5 лет назад

An issue was discovered in Zammad before 3.4.1. There is an authentica ...

EPSS

Процентиль: 65%
0.00494
Низкий

Дефекты

CWE-287