CVE-2024-9665: Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9665?
CVE-2024-9665 has been rated as a medium severity vulnerability.
How do I fix CVE-2024-9665?
To fix CVE-2024-9665, update your Zimbra installation to the latest version as recommended by the vendor.
What type of information can be disclosed due to CVE-2024-9665?
CVE-2024-9665 may allow unauthorized access to sensitive information within the user's email account.
Is user interaction required to exploit CVE-2024-9665?
Yes, user interaction is required as the target must open a malicious email message to exploit CVE-2024-9665.
Which versions of Zimbra are affected by CVE-2024-9665?
CVE-2024-9665 affects Zimbra versions prior to 9.0.0 and those between 10.0.0 and 10.1.2.