CVE-2023-41106: High severity Zimbra Collaboration vulnerability
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41106?
CVE-2023-41106 has been categorized as a critical vulnerability due to its potential to allow unauthorized access to Zimbra accounts.
How do I fix CVE-2023-41106?
To fix CVE-2023-41106, you should upgrade your Zimbra Collaboration instance to version 10.0.3 or later, or apply Patch 35 for version 9.0.0 or Patch 42 for version 8.8.15.
Who is affected by CVE-2023-41106?
CVE-2023-41106 affects all versions of Zimbra Collaboration prior to 10.0.3, including specific patches of versions 8.8.15 and 9.0.0.
What type of vulnerability is CVE-2023-41106?
CVE-2023-41106 is an authorization flaw that could allow attackers to gain access to sensitive Zimbra account information.
Is there a workaround for CVE-2023-41106?
There are no known workarounds for CVE-2023-41106 other than applying the recommended updates and patches promptly.