6.5

CVE-2024-9665

Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability

Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message.

The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account. Was ZDI-CAN-23939.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zimbra ≫ Zimbra Version < 9.0.0
Zimbra ≫ Zimbra Version >= 10.0.0 < 10.0.10
Zimbra ≫ Zimbra Version >= 10.1.0 < 10.1.2
Zimbra ≫ Zimbra Version 9.0.0 Update p0
Zimbra ≫ Zimbra Version 9.0.0 Update p19
Zimbra ≫ Zimbra Version 9.0.0 Update p23
Zimbra ≫ Zimbra Version 9.0.0 Update p25
Zimbra ≫ Zimbra Version 9.0.0 Update p26
Zimbra ≫ Zimbra Version 9.0.0 Update p27
Zimbra ≫ Zimbra Version 9.0.0 Update p28
Zimbra ≫ Zimbra Version 9.0.0 Update p30
Zimbra ≫ Zimbra Version 9.0.0 Update p31
Zimbra ≫ Zimbra Version 9.0.0 Update p33
Zimbra ≫ Zimbra Version 9.0.0 Update p34
Zimbra ≫ Zimbra Version 9.0.0 Update p35
Zimbra ≫ Zimbra Version 9.0.0 Update p36
Zimbra ≫ Zimbra Version 9.0.0 Update p37
Zimbra ≫ Zimbra Version 9.0.0 Update p38
Zimbra ≫ Zimbra Version 9.0.0 Update p39
Zimbra ≫ Zimbra Version 9.0.0 Update p4
Zimbra ≫ Zimbra Version 9.0.0 Update p40
Zimbra ≫ Zimbra Version 9.0.0 Update p41
Zimbra ≫ Zimbra Version 9.0.0 Update p7
Zimbra ≫ Zimbra Version 9.0.0 Update p7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.366
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Trend Micro 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://blog.zimbra.com/2024/10/new-patch-release-reminders-for-missing-attachments-out-of-office-notifications-traffic-light-protocol-tlp-and-mailto-links/
Release Notes
https://www.zerodayinitiative.com/advisories/ZDI-24-1369/
Third Party Advisory