CVE-2025-25065: SSRF
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zimbra Collaborationto a version that resolves this vulnerability.Fixed in 9.0.0Patch Patch 43 - Upgrade
Upgrade
Zimbra Collaborationto a version that resolves this vulnerability.Fixed in 10.0.12 - Upgrade
Upgrade
Zimbra Collaborationto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25065?
CVE-2025-25065 has a medium severity rating as it allows unauthorized access to internal resources.
How do I fix CVE-2025-25065?
To fix CVE-2025-25065, upgrade to Zimbra Collaboration version 9.0.0 Patch 43 or later, version 10.0.12 or later, or version 10.1.4 or later.
Which versions of Zimbra are affected by CVE-2025-25065?
CVE-2025-25065 affects Zimbra Collaboration versions prior to 9.0.0 Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4.
What type of vulnerability is CVE-2025-25065?
CVE-2025-25065 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Can CVE-2025-25065 lead to data exposure?
Yes, CVE-2025-25065 can potentially lead to unauthorized access and exposure of internal network endpoints.