CERT-In Vulnerability Note
CIVN-2023-0390
Multiple Vulnerabilities in Zimbra Collaboration
Original Issue Date:December 28, 2023
Severity Rating: HIGH
Software Affected
- Zimbra Collaboration Joule prior to 8.8.15 Patch 45 GA
- Zimbra Collaboration Kepler prior to 9.0.0 Patch 38 GA
- Zimbra Collaboration Daffodil prior to 10.0.6
Overview
Multiple vulnerabilities have been reported in Zimbra Collaboration. A remote attacker could exploit some of these vulnerabilities to conduct cross-site scripting attacks, bypass security restriction and access or modify data without authorization on a targeted system.
Description
These vulnerabilities exist in Zimbra Collaboration due to dependency on older and vulnerable OpenJDK package (version 17.0.2), as well as other software security issues in Zimbra Collaboration itself.
Successful exploitation of these vulnerabilities could allow a remote attacker to conduct cross-site scripting attacks, bypass security restriction and access or modify data without authorization on the targeted system.
Solution
Update to patched versions released by Zimbra:
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P45
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P38
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.6
Vendor Information
Zimbra
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P45
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P38
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.6
CVE Name
CVE-2023-21930
CVE-2022-21476
CVE-2022-21449
CVE-2023-48432
CVE-2023-50808
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|