Security Advisory

CVE-2024-33667

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-26 00:00:00
Last updated 2024-11-25 18:52:02
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.