CVE-2022-41352 - Synacor Zimbra Collaboration Suite (ZCS)
AI Vulnerability ContextAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation af...
Overview
A source-backed snapshot of this vulnerability.
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2022-41352
- Vendor/project
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- Vulnerability name
- Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
- Date added
- 2022-10-20
- Due date
- 2022-11-10
- Known ransomware campaign use
- Unknown
- CVSS v3
- 9.8
Exploit context
What the vulnerability is about.
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
