An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
{
"versions": [
{
"introduced": "6.2.0"
},
{
"fixed": "6.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "6.3.0-alpha"
}
]
}