HackerFeeds
All CVEs

CVE-2022-41352

CRITICAL9.8
CISA KEV

Published 2022-09-26 · Updated 2026-09-10 · Source cve@mitre.org

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-22CWE-22

CISA Known-Exploited Vulnerability

Product: SynacorZimbra Collaboration Suite (ZCS)

Name: Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Date added: 2022-10-20 · Due: 2022-11-10

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD