6.5

CVE-2020-10194

cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zimbra ≫ Zm-mailbox Version < 8.8.15
Zimbra ≫ Zm-mailbox Version 8.8.15 Update -
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch1
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch2
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch3
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch4
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch5
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch6
Zimbra ≫ Zm-mailbox Version 8.8.15 Update patch7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.644
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1e
Patch
Third Party Advisory
https://github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8
Patch
Third Party Advisory
https://github.com/Zimbra/zm-mailbox/pull/1020
Patch
Third Party Advisory