ZeroHour

CVE-2020-10101

CVSS 3.1
7.5 high
EPSS
1%p63
Published
()
Modified
Description

An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors not handled. This leads to a crash of the service process.

Vendors
zammad
Products
zammad
Weakness
CWE-20, CWE-755
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.