CVE-2024-33535: Path Traversal
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication, potentially leading to unauthorized access to sensitive information. The vulnerability is limited to files within a specific directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33535?
CVE-2024-33535 is classified as a high severity vulnerability due to the potential for unauthenticated local file inclusion.
How do I fix CVE-2024-33535?
To fix CVE-2024-33535, it is recommended to update Zimbra Collaboration to the latest patched version as specified by the vendor.
What systems are affected by CVE-2024-33535?
CVE-2024-33535 affects Zimbra Collaboration versions 9.0 (up to and including 9.0.0-p39) and 10.0 (up to and including 10.0.8).
Can CVE-2024-33535 be exploited remotely?
Yes, CVE-2024-33535 can be remotely exploited by attackers to include arbitrary local files without authentication.
Is there a workaround for CVE-2024-33535?
Currently, the best approach is to apply the official patches provided by Zimbra, as effective workarounds may not be available.