CVE-2021-34807: Medium severity zimbra collaboration suite vulnerability
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could redirect a user to any URL via isredirect=1&redirectURL= in conjunction with the token data (e.g., a valid authtoken= value).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34807?
CVE-2021-34807 is an open redirect vulnerability that exists in the /preauth Servlet in Zimbra Collaboration Suite through version 9.0.
How does CVE-2021-34807 vulnerability work?
To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token and redirect a user to any URL.
What is the severity level of CVE-2021-34807?
The severity level of CVE-2021-34807 is medium, with a CVSS score of 6.1.
Which versions of Zimbra Collaboration Suite are affected by CVE-2021-34807?
Zimbra Collaboration Suite versions up to and including 9.0 are affected by CVE-2021-34807.
How can I fix CVE-2021-34807 vulnerability?
Ensure you are using a version of Zimbra Collaboration Suite that is patched to a version containing the fix, such as version 8.8.15-p23 or 9.0.0-p16.