CVE-2024-45519: Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.
Other sources
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) postjournal serviceto a version that resolves this vulnerability.Fixed in 8.8.15 Patch 46 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) postjournal serviceto a version that resolves this vulnerability.Fixed in 9.0.0 Patch 41 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) postjournal serviceto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) postjournal serviceto a version that resolves this vulnerability.Fixed in 10.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45519?
CVE-2024-45519 is a critical vulnerability that allows unauthenticated users to execute commands on affected Zimbra Collaboration servers.
How do I fix CVE-2024-45519?
To mitigate CVE-2024-45519, you should upgrade to Zimbra Collaboration versions 8.8.15 Patch 46, 9.0.0 Patch 41, or 10.0.9 or later.
Which versions of Synacor Zimbra Collaboration are affected by CVE-2024-45519?
CVE-2024-45519 affects Synacor Zimbra Collaboration versions before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, and 10 before 10.0.9.
Can CVE-2024-45519 be exploited remotely?
Yes, CVE-2024-45519 can be exploited remotely by unauthenticated users to execute arbitrary commands.
What are the consequences of exploiting CVE-2024-45519?
Exploitation of CVE-2024-45519 may lead to unauthorized access and control over the affected Zimbra Collaboration servers.