Why teams of all sizes choose Zammad for structured, reliable support.
Zammad 7.2.2
· Zammad 7.2.2 is an important security update. It addresses a vulnerability that only affects DEB/RPM packages (packager.io).
Below, you’ll find all relevant information about the update and the required steps.
Recommended Resolution
SaaS Customers: No action is required. Your instances are not affected.
Self-Hosted Installations: We strongly advise upgrading to the latest version of Zammad immediately to ensure your system is protected.
Vulnerabilities patched
For full technical details, please refer to the security advisories on GitHub.
- Local privilege escalation to root in DEB/RPM packages (packager.io): The vulnerability only affects installations using DEB/RPM packages and, under certain local conditions, could allow user privileges to be escalated.
📣 Important Announcements Regarding Upcoming Releases
String#utf8_encode and Object#to_utf8 will be removed
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#stringutf8_encode-and-objectto_utf8-will-be-removed
Debian 11 will no longer be supported
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#debian-11-will-no-longer-be-supported
Inline attachments will be listed separately in ticket article API responses
Exceptions::UnprocessableEntity will be removed
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#exceptionsunprocessableentity-will-be-removed
The deprecated Rails.application.config.db_* values will be removed
String#utf8_encode and Object#to_utf8 will be deprecated in favour of TextEncoding.utf8_encode
Import mode will also enable maintenance mode
All details: https://github.com/zammad/zammad/blob/develop/BREAKING_CHANGES.md#import-mode-also-enables-maintenance-mode