Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52815 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. |
| Link | Providers |
|---|---|
| https://zammad.com/en/advisories/zaa-2024-05 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zammad
Zammad zammad |
|
| CPEs | cpe:2.3:a:zammad:zammad:6.4.0:-:*:*:*:*:*:* cpe:2.3:a:zammad:zammad:6.4.0:alpha:*:*:*:*:*:* |
|
| Vendors & Products |
Zammad
Zammad zammad |
Thu, 12 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-12T17:15:13.116Z
Reserved: 2024-12-09T00:00:00.000Z
Link: CVE-2024-55578
Updated: 2024-12-12T17:15:05.613Z
Status : Analyzed
Published: 2024-12-09T03:15:04.530
Modified: 2025-04-15T16:37:30.420
Link: CVE-2024-55578
No data.
OpenCVE Enrichment
No data.
EUVD