VYPR
Medium severity6.7NVD Advisory· Published May 19, 2024· Updated Jun 17, 2026

CVE-2024-36078

CVE-2024-36078

Description

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Zammad/Zammad4 versions
    cpe:2.3:a:zammad:zammad:6.3.0:-:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:zammad:zammad:6.3.0:-:*:*:*:*:*:*
    • cpe:2.3:a:zammad:zammad:6.3.0:alpha:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <6.3.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.