In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.
References
Link | Resource |
---|---|
https://zammad.com/en/advisories/zaa-2021-21 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-04T14:21:17
Updated: 2022-02-04T14:21:17
Reserved: 2021-12-13T00:00:00
Link: CVE-2021-44886
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-02-04T15:15:12.793
Modified: 2023-08-08T14:22:24.967
Link: CVE-2021-44886
JSON object: View
Redhat Information
No data.
CWE