CVE-2022-41352: Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure the pax package is installed so that amavis automatically prefers pax over cpio, per Zimbra's recommendation (Zimbra Collaboration Suite arbitrary file upload vulnerability via cpio loophole).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-41352?
CVE-2022-41352 is a vulnerability that allows an attacker to upload arbitrary files using the cpio package in Zimbra Collaboration (ZCS).
How does CVE-2022-41352 work?
CVE-2022-41352 allows an attacker to gain incorrect access to any other user accounts by uploading arbitrary files using the cpio package in Zimbra Collaboration (ZCS).
What software is affected by CVE-2022-41352?
Zimbra Collaboration (ZCS) is affected by CVE-2022-41352.
How severe is CVE-2022-41352?
CVE-2022-41352 is a serious vulnerability that can lead to unauthorized access to user accounts in Zimbra Collaboration (ZCS).
How can I fix CVE-2022-41352?
To fix CVE-2022-41352, it is recommended to apply the latest security patches or updates provided by Zimbra.