ZDI-CAN-23939: ZDI-24-1369: Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-9665.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23939?
The severity of ZDI-CAN-23939 is classified as medium due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-23939?
To fix ZDI-CAN-23939, users should apply the latest patch provided by Zimbra for their installation.
What type of attack vector does ZDI-CAN-23939 involve?
ZDI-CAN-23939 involves a user interaction attack vector that requires the target to open a malicious email message.
What versions of Zimbra are affected by ZDI-CAN-23939?
ZDI-CAN-23939 affects specific versions of Zimbra, particularly those before the security patch was applied.
What is the impact of ZDI-CAN-23939 if exploited?
If exploited, ZDI-CAN-23939 allows remote attackers to disclose sensitive information from the affected Zimbra installations.