CVE-2024-45518
largeAuthenticated SSRF in Zimbra Collaboration Suite can chain to RCE
Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) flaw, CVE-2024-45518, caused by improper input sanitization and a misconfigured domain whitelist. An authenticated user with only low-level privileges can trigger the flaw to make the Zimbra server send unauthorized HTTP requests to services on the internal network. By chaining the SSRF with command injection in a reachable internal service, the attacker can achieve remote code execution; combining the SSRF with existing cross-site scripting vulnerabilities also yields RCE. All supported ZCS branches are affected: 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the elevated EPSS score (20.7% probability of exploitation in 30 days, 97th percentile) indicates significant exploitation risk.
What to do: Upgrade to ZCS 10.1.1, 10.0.9, 9.0.0 Patch 41, or 8.8.15 Patch 46 (or later) to remediate. Until patched, enforce a strict and correctly configured domain whitelist for the affected feature, map which internal services the Zimbra host can reach, and monitor for anomalous internal HTTP requests originating from the server. Since authentication is required, review accounts on internet-exposed webmail for low-privilege or compromised credentials that could be used as a launch point.
| Zimbra Collaboration Suite (ZCS) | 10.1.x before 10.1.1; 10.0.x before 10.0.9; 9.0.0 before Patch 41; 8.8.15 before Patch 46 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).
- Vendors
- zimbra
- Products
- collaboration
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.