First published: Fri Nov 22 2024(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Zimbra | ||
Zimbra Zimbra | <9.0.0 | |
Zimbra Zimbra | >=10.0.0<10.0.10 | |
Zimbra Zimbra | >=10.1.0<10.1.2 | |
Zimbra Zimbra | =9.0.0-p0 | |
Zimbra Zimbra | =9.0.0-p19 | |
Zimbra Zimbra | =9.0.0-p23 | |
Zimbra Zimbra | =9.0.0-p25 | |
Zimbra Zimbra | =9.0.0-p26 | |
Zimbra Zimbra | =9.0.0-p27 | |
Zimbra Zimbra | =9.0.0-p28 | |
Zimbra Zimbra | =9.0.0-p30 | |
Zimbra Zimbra | =9.0.0-p31 | |
Zimbra Zimbra | =9.0.0-p33 | |
Zimbra Zimbra | =9.0.0-p34 | |
Zimbra Zimbra | =9.0.0-p35 | |
Zimbra Zimbra | =9.0.0-p36 | |
Zimbra Zimbra | =9.0.0-p37 | |
Zimbra Zimbra | =9.0.0-p38 | |
Zimbra Zimbra | =9.0.0-p39 | |
Zimbra Zimbra | =9.0.0-p4 | |
Zimbra Zimbra | =9.0.0-p40 | |
Zimbra Zimbra | =9.0.0-p41 | |
Zimbra Zimbra | =9.0.0-p7 | |
Zimbra Zimbra | =9.0.0-p7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.