Zammad (Multiple Products)


Vendor Data
Community Data Vulnerable

Vendor Resources

Resource Link
Zammad Elasticsearch Users https://community.zammad.org/t/cve-2021-44228-elasticsearch-users-be-aware/8256

Community Resources

Resource Link
source https://community.zammad.org/t/cve-2021-44228-elasticsearch-users-be-aware/8256

Community Notes

Source Note
NCSC-NL CVE-2021-4104: Not vuln ; CVE-2021-44228: Workaround
NCSC-NL Most of Zammad instances make use of Elasticsearch which might be vulnerable.

Sources

Date Attribution Description
2021-12-27 15:29:04 NCSC-NL Updated communityVulnerable. Updated community note. Updated community link source. Updated community note.
2021-12-30 21:31:50 CISAGov Updated vendor link Zammad Elasticsearch Users.