CVE-2025-67809: Medium severity Zimbra Collaboration vulnerability
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67809?
CVE-2025-67809 has a high severity due to the presence of a hardcoded Flickr API key and secret in Zimbra Collaboration.
How do I fix CVE-2025-67809?
To fix CVE-2025-67809, you should update to a patched version of Zimbra Collaboration that removes the hardcoded API credentials.
What versions are affected by CVE-2025-67809?
CVE-2025-67809 affects Zimbra Collaboration versions 10.0 and 10.1.
What potential risks are associated with CVE-2025-67809?
The risks include unauthorized access and exploitation of the exposed Flickr API key, which could lead to data breaches or service disruption.
Is there a workaround for CVE-2025-67809 until I can update?
Disabling the affected Flickr Zimlet can serve as a temporary workaround while you plan to update Zimbra Collaboration.