Why teams of all sizes choose Zammad for structured, reliable support.
Zammad 7.2.1
· Zammad 7.2.1 is an important security update that addresses critical vulnerabilities. Below you will find all the relevant information about the update and the required steps.
Recommended Resolution
SaaS Customers: No action is required. Your instances have already been patched and secured by our team.
Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.
Vulnerabilities patched
For full technical details, please refer to the security advisories on GitHub.
- Stored XSS in desktop autocomplete fields via unescaped option label
- Multi-factor authentication could be bypassed through the email verification flow
- Stored XSS in desktop tree select fields via whitespace-only filter
- Group collection push disclosed full group records to any authenticated session
- Password reset endpoint disclosed whether an account existed via response timing
- Activity stream disclosed content of tickets moved out of an agent's groups
- Group configuration and email address disclosure to authenticated users via getting started endpoint
- Ticket link list disclosed the existence and relation of tickets outside the user's permission scope
- Ticket data of no-longer-accessible tickets disclosed to agents via online notification API
- Disclosure of names of users from other organizations to customers
- Deactivated roles still granted ticket group access in overviews and search
- Deactivated roles still granted knowledge base editor access
- Session identifier disclosed in authenticated configuration response enabled off-host session takeover
- Inactive sessions remain authorized over ActionCable GraphQL
- User-controlled attachment content type weakens the script-source protection
- Remote code execution via template sanitizer bypass in automation configuration
- Unfiltered sign-up and ticket update fields allow cross-organization ticket disclosure and takeover
- Stored XSS in ticket zoom via attacker-controlled article preferences
- Arbitrary configuration disclosure via recent view endpoint
- Second-order SQL injection in ticket overview sorting
- Unscoped GraphQL template query and subscription bypass TemplatePolicy scope
- Stored HTML injection in Knowledge Base video widget rendered inside Zammad enables forced session switching
- Missing authorization on ticket articles can expose article content to unauthorized users
- Channel administration APIs return stored channel credentials in clear text
- Forward quote header discloses agent email addresses
- Clipboard HTML injection via unescaped user and organization display name
- Customer-visible ticket update responses leak unredacted user and organization data
- Knowledge base reordering, publishing and administration possible without the required permission
📣 Important Announcements
String#utf8_encode and Object#to_utf8 will be removed
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#stringutf8_encode-and-objectto_utf8-will-be-removed
Debian 11 will no longer be supported
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#debian-11-will-no-longer-be-supported
Inline attachments will be listed separately in ticket article API responses
Exceptions::UnprocessableEntity will be removed
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#exceptionsunprocessableentity-will-be-removed
The deprecated Rails.application.config.db_* values will be removed
String#utf8_encode and Object#to_utf8 will be deprecated in favour of TextEncoding.utf8_encode
Import mode will also enable maintenance mode
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#import-mode-also-enables-maintenance-mode