CVE-2024-45518: SSRF
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45518?
CVE-2024-45518 is classified as a moderate severity vulnerability due to the potential for authenticated users to exploit Server-Side Request Forgery.
How do I fix CVE-2024-45518?
To fix CVE-2024-45518, it is essential to upgrade Zimbra Collaboration to version 10.1.1 or newer, or apply the relevant patches for the affected versions.
What versions of Zimbra Collaboration are affected by CVE-2024-45518?
CVE-2024-45518 affects Zimbra Collaboration versions 10.1.0, earlier than 10.1.1, any versions before 10.0.9, any 9.0.0 versions before Patch 41, and versions prior to 8.8.15 Patch 46.
What is Server-Side Request Forgery in the context of CVE-2024-45518?
In the context of CVE-2024-45518, Server-Side Request Forgery allows an authenticated attacker to send crafted requests that may lead to unauthorized access to sensitive internal resources.
Can an unauthenticated user exploit CVE-2024-45518?
No, CVE-2024-45518 requires authentication, meaning that only authenticated users can attempt to exploit this particular vulnerability.