First published: Mon Aug 12 2024(Updated: )
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication, potentially leading to unauthorized access to sensitive information. The vulnerability is limited to files within a specific directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration | >=10.0.0<10.0.8 | |
Zimbra Collaboration | =9.0.0 | |
Zimbra Collaboration | =9.0.0-p0 | |
Zimbra Collaboration | =9.0.0-p1 | |
Zimbra Collaboration | =9.0.0-p10 | |
Zimbra Collaboration | =9.0.0-p11 | |
Zimbra Collaboration | =9.0.0-p12 | |
Zimbra Collaboration | =9.0.0-p13 | |
Zimbra Collaboration | =9.0.0-p14 | |
Zimbra Collaboration | =9.0.0-p15 | |
Zimbra Collaboration | =9.0.0-p16 | |
Zimbra Collaboration | =9.0.0-p19 | |
Zimbra Collaboration | =9.0.0-p2 | |
Zimbra Collaboration | =9.0.0-p20 | |
Zimbra Collaboration | =9.0.0-p21 | |
Zimbra Collaboration | =9.0.0-p23 | |
Zimbra Collaboration | =9.0.0-p24 | |
Zimbra Collaboration | =9.0.0-p24.1 | |
Zimbra Collaboration | =9.0.0-p25 | |
Zimbra Collaboration | =9.0.0-p26 | |
Zimbra Collaboration | =9.0.0-p27 | |
Zimbra Collaboration | =9.0.0-p3 | |
Zimbra Collaboration | =9.0.0-p30 | |
Zimbra Collaboration | =9.0.0-p31 | |
Zimbra Collaboration | =9.0.0-p32 | |
Zimbra Collaboration | =9.0.0-p33 | |
Zimbra Collaboration | =9.0.0-p34 | |
Zimbra Collaboration | =9.0.0-p35 | |
Zimbra Collaboration | =9.0.0-p36 | |
Zimbra Collaboration | =9.0.0-p37 | |
Zimbra Collaboration | =9.0.0-p38 | |
Zimbra Collaboration | =9.0.0-p39 | |
Zimbra Collaboration | =9.0.0-p4 | |
Zimbra Collaboration | =9.0.0-p5 | |
Zimbra Collaboration | =9.0.0-p6 | |
Zimbra Collaboration | =9.0.0-p7 | |
Zimbra Collaboration | =9.0.0-p7.1 | |
Zimbra Collaboration | =9.0.0-p8 | |
Zimbra Collaboration | =9.0.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33535 is classified as a high severity vulnerability due to the potential for unauthenticated local file inclusion.
To fix CVE-2024-33535, it is recommended to update Zimbra Collaboration to the latest patched version as specified by the vendor.
CVE-2024-33535 affects Zimbra Collaboration versions 9.0 (up to and including 9.0.0-p39) and 10.0 (up to and including 10.0.8).
Yes, CVE-2024-33535 can be remotely exploited by attackers to include arbitrary local files without authentication.
Currently, the best approach is to apply the official patches provided by Zimbra, as effective workarounds may not be available.