First published: Fri Nov 22 2024(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | ||
Zimbra Collaboration Suite | <9.0.0 | |
Zimbra Collaboration Suite | >=10.0.0<10.0.10 | |
Zimbra Collaboration Suite | >=10.1.0<10.1.2 | |
Zimbra Collaboration Suite | =9.0.0-p0 | |
Zimbra Collaboration Suite | =9.0.0-p19 | |
Zimbra Collaboration Suite | =9.0.0-p23 | |
Zimbra Collaboration Suite | =9.0.0-p25 | |
Zimbra Collaboration Suite | =9.0.0-p26 | |
Zimbra Collaboration Suite | =9.0.0-p27 | |
Zimbra Collaboration Suite | =9.0.0-p28 | |
Zimbra Collaboration Suite | =9.0.0-p30 | |
Zimbra Collaboration Suite | =9.0.0-p31 | |
Zimbra Collaboration Suite | =9.0.0-p33 | |
Zimbra Collaboration Suite | =9.0.0-p34 | |
Zimbra Collaboration Suite | =9.0.0-p35 | |
Zimbra Collaboration Suite | =9.0.0-p36 | |
Zimbra Collaboration Suite | =9.0.0-p37 | |
Zimbra Collaboration Suite | =9.0.0-p38 | |
Zimbra Collaboration Suite | =9.0.0-p39 | |
Zimbra Collaboration Suite | =9.0.0-p4 | |
Zimbra Collaboration Suite | =9.0.0-p40 | |
Zimbra Collaboration Suite | =9.0.0-p41 | |
Zimbra Collaboration Suite | =9.0.0-p7 | |
Zimbra Collaboration Suite | =9.0.0-p7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9665 has been rated as a medium severity vulnerability.
To fix CVE-2024-9665, update your Zimbra installation to the latest version as recommended by the vendor.
CVE-2024-9665 may allow unauthorized access to sensitive information within the user's email account.
Yes, user interaction is required as the target must open a malicious email message to exploit CVE-2024-9665.
CVE-2024-9665 affects Zimbra versions prior to 9.0.0 and those between 10.0.0 and 10.1.2.