An issue was discovered in Zammad before 6.2.0. It uses the public endpoint /api/v1/signshow for its login screen. This endpoint returns internal configuration data of user object attributes, such as selectable values, which should not be visible to the public.
References
Link Resource
https://zammad.com/en/advisories/zaa-2023-08 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-10T00:00:00

Updated: 2023-12-10T18:49:39.031213

Reserved: 2023-12-10T00:00:00


Link: CVE-2023-50453

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-10T19:15:07.480

Modified: 2023-12-13T15:58:08.647


Link: CVE-2023-50453

JSON object: View

cve-icon Redhat Information

No data.