ZeroHour

CVE-2024-45518

large

Authenticated SSRF in Zimbra Collaboration Suite can chain to RCE

CVSS 3.1
8.8 high
EPSS
21%p97
Published
()
Modified
AI analysis

Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) flaw, CVE-2024-45518, caused by improper input sanitization and a misconfigured domain whitelist. An authenticated user with only low-level privileges can trigger the flaw to make the Zimbra server send unauthorized HTTP requests to services on the internal network. By chaining the SSRF with command injection in a reachable internal service, the attacker can achieve remote code execution; combining the SSRF with existing cross-site scripting vulnerabilities also yields RCE. All supported ZCS branches are affected: 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the elevated EPSS score (20.7% probability of exploitation in 30 days, 97th percentile) indicates significant exploitation risk.

What to do: Upgrade to ZCS 10.1.1, 10.0.9, 9.0.0 Patch 41, or 8.8.15 Patch 46 (or later) to remediate. Until patched, enforce a strict and correctly configured domain whitelist for the affected feature, map which internal services the Zimbra host can reach, and monitor for anomalous internal HTTP requests originating from the server. Since authentication is required, review accounts on internet-exposed webmail for low-privilege or compromised credentials that could be used as a launch point.

Affected
Zimbra Collaboration Suite (ZCS)10.1.x before 10.1.1; 10.0.x before 10.0.9; 9.0.0 before Patch 41; 8.8.15 before Patch 46
Estimated exposure
largetens of thousands of deployments (public internet scans typically index roughly 30,000-50,000 exposed Zimbra servers) — ZCS is a widely self-hosted enterprise mail/collaboration platform, and the affected version ranges span every supported branch, so essentially all unpatched ZCS installations visible to internet-wide scans are in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).

Vendors
zimbra
Products
collaboration
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.