Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1029

NIXPKGS-2026-1029
published 2 months, 2 weeks ago
updated 2 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.zammad-py
    • python313Packages.zammad-py
    • python314Packages.zammad-py
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.

Affected products

zammad
  • ==>= 7.0.0-alpha, < 7.0.1
  • ==< 6.5.4

Matching in nixpkgs

pkgs.zammad

Web-based, open source user support/ticketing solution

Ignored packages (3)

Package maintainers