VYPR
Unrated severityNVD Advisory· Published May 19, 2024· Updated Feb 13, 2025

CVE-2024-36078

CVE-2024-36078

Description

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Zammad/Zammadcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <6.3.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.