warum Teams jeder Größe Zammad für strukturierten, zuverlässigen Support wählen.
Zammad 7.2.1
· Mit Zammad 7.2.1 steht ein wichtiges Sicherheitsupdate bereit. Es schließt kritische Schwachstellen und sollte daher zeitnah installiert werden.
Im Folgenden finden Sie alle Informationen zum Update und zu den erforderlichen Schritten.
Empfohlene Maßnahme
SaaS-Kunden: Es sind keine Schritte erforderlich. Ihre Instanzen wurden bereits durch unser Team aktualisiert und abgesichert.
Selbst gehostete Installationen: Wir empfehlen dringend, Ihr System umgehend auf die neueste Zammad-Version zu aktualisieren, um den Schutz Ihrer Installation sicherzustellen.
Behobene Sicherheitslücken
Alle technischen Details finden Sie in den Security Advisories auf GitHub.
- Stored XSS in desktop autocomplete fields via unescaped option label
- Multi-factor authentication could be bypassed through the email verification flow
- Stored XSS in desktop tree select fields via whitespace-only filter
- Group collection push disclosed full group records to any authenticated session
- Password reset endpoint disclosed whether an account existed via response timing
- Activity stream disclosed content of tickets moved out of an agent's groups
- Group configuration and email address disclosure to authenticated users via getting started endpoint
- Ticket link list disclosed the existence and relation of tickets outside the user's permission scope
- Ticket data of no-longer-accessible tickets disclosed to agents via online notification API
- Disclosure of names of users from other organizations to customers
- Deactivated roles still granted ticket group access in overviews and search
- Deactivated roles still granted knowledge base editor access
- Session identifier disclosed in authenticated configuration response enabled off-host session takeover
- Inactive sessions remain authorized over ActionCable GraphQL
- User-controlled attachment content type weakens the script-source protection
- Remote code execution via template sanitizer bypass in automation configuration
- Unfiltered sign-up and ticket update fields allow cross-organization ticket disclosure and takeover
- Stored XSS in ticket zoom via attacker-controlled article preferences
- Arbitrary configuration disclosure via recent view endpoint
- Second-order SQL injection in ticket overview sorting
- Unscoped GraphQL template query and subscription bypass TemplatePolicy scope
- Stored HTML injection in Knowledge Base video widget rendered inside Zammad enables forced session switching
- Missing authorization on ticket articles can expose article content to unauthorized users
- Channel administration APIs return stored channel credentials in clear text
- Forward quote header discloses agent email addresses
- Clipboard HTML injection via unescaped user and organization display name
- Customer-visible ticket update responses leak unredacted user and organization data
- Knowledge base reordering, publishing and administration possible without the required permission
📣 Wichtige Ankündigungen
String#utf8_encode und Object#to_utf8 werden entfernt
Alle Details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#stringutf8_encode-and-objectto_utf8-will-be-removed
Debian 11 wird nicht mehr unterstützt
Alle Details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#debian-11-will-no-longer-be-supported
Inline-Anhänge werden in API-Antworten zu Ticket-Artikeln separat aufgeführt
Exceptions::UnprocessableEntity wird entfernt
Alle Details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#exceptionsunprocessableentity-will-be-removed
Die veralteten Rails.application.config.db_*-Werte werden entfernt
String#utf8_encode und Object#to_utf8 werden zugunsten von TextEncoding.utf8_encode abgeschafft
Der Importmodus wird gleichzeitig den Wartungsmodus aktivieren
Alle Details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#import-mode-also-enables-maintenance-mode