6.5

CVE-2024-9665

Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message.

The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account. Was ZDI-CAN-23939.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZimbraZimbra Version < 9.0.0
ZimbraZimbra Version >= 10.0.0 < 10.0.10
ZimbraZimbra Version >= 10.1.0 < 10.1.2
ZimbraZimbra Version9.0.0 Updatep0
ZimbraZimbra Version9.0.0 Updatep19
ZimbraZimbra Version9.0.0 Updatep23
ZimbraZimbra Version9.0.0 Updatep25
ZimbraZimbra Version9.0.0 Updatep26
ZimbraZimbra Version9.0.0 Updatep27
ZimbraZimbra Version9.0.0 Updatep28
ZimbraZimbra Version9.0.0 Updatep30
ZimbraZimbra Version9.0.0 Updatep31
ZimbraZimbra Version9.0.0 Updatep33
ZimbraZimbra Version9.0.0 Updatep34
ZimbraZimbra Version9.0.0 Updatep35
ZimbraZimbra Version9.0.0 Updatep36
ZimbraZimbra Version9.0.0 Updatep37
ZimbraZimbra Version9.0.0 Updatep38
ZimbraZimbra Version9.0.0 Updatep39
ZimbraZimbra Version9.0.0 Updatep4
ZimbraZimbra Version9.0.0 Updatep40
ZimbraZimbra Version9.0.0 Updatep41
ZimbraZimbra Version9.0.0 Updatep7
ZimbraZimbra Version9.0.0 Updatep7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
zdi-disclosures@trendmicro.com 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.