CERT-In Vulnerability Note
CIVN-2022-0401
Multiple Vulnerabilities in Zimbra
Original Issue Date:October 20, 2022
Severity Rating: HIGH
Software Affected
- Zimbra versions prior to 9.0.0 Patch 27
- Zimbra versions prior to 8.8.15 Patch 34
Overview
Multiple vulnerabilities have been reported in Zimbra Collaboration software which could be exploited by an attacker to gain elevated privileges, execute arbitrary code, disclose sensitive information and bypass security restrictions on the target system.
Description
1. Remote Code Execution Vulnerability
(
CVE-2022-41352
)
This vulnerability exists in Zimbra Collaboration due to improper validation of file extensions. An attacker could exploit this vulnerability by executing a specially crafted request to upload malicious files. Successful exploitation of the vulnerability could allow the attacker to execute arbitrary code on the targeted system.
2. Cross Site Scripting Vulnerability
(
CVE-2022-41349
CVE-2022-41348
CVE-2022-41350
CVE-2022-41351
)
These vulnerabilities exist in Zimbra Collaboration due to improper validation in the attribute of IMG element, search component, calendar component and compose component of webmail. An attacker could exploit these vulnerabilities using a specially-crafted URL to execute a script in a victims Web browser. Successful exploitation of these vulnerabilities could allow attacker to gain access to sensitive information on the targeted system.
3. Privilege Escalation Vulnerability
(
CVE-2022-37393
)
This vulnerability exists in Zimbra due to a flaw in the sudo configuration. A local authenticated attacker could exploit this vulnerability by sending a specially crafted request. Successful exploitation of this vulnerability could allow local authenticated attacker to gain elevated privileges on the targeted system.
Solution
Apply appropriate software fixes as available on the vendor website.
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P34
Vendor Information
Zimbra
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://blog.zimbra.com/2022/10/new-zimbra-patches-9-0-0-patch-27-8-8-15-patch-34/
References
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://blog.zimbra.com/2022/10/new-zimbra-patches-9-0-0-patch-27-8-8-15-patch-34/
https://www.securityweek.com/zimbra-patches-under-attack-code-execution-bug
CVE Name
CVE-2022-41352
CVE-2022-41348
CVE-2022-41349
CVE-2022-41350
CVE-2022-41351
CVE-2022-37393
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|