QID 377618
Date Published: 2022-10-08
QID 377618: Zimbra Collaboration Remote Code Execution (RCE) Vulnerability
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts.
Affected Software:
Zimbra Collaboration Suite 8.8.15
Zimbra Collaboration Suite 9.0
QID Detection Logic:
This QID checks the vulnerable version of Zimbra and the status of pax command.
Successful exploitation could allow an attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts.
CVEs related to QID 377618
| Advisory ID | Software | Component | Link |
|---|