CVE-2024-36078

MEDIUM

Zammad < 6.3.1 - Local Code Injection via World-Writable Gem Files

Title source: llm
STIX 2.1

Description

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
zammad/zammad 6.3.0 (2 CPE variants)
Published May 19, 2024
Tracked Since Feb 18, 2026