PT-2023-22235 · Zimbra · Zimbra Collaboration

CVE-2023-29381

·

Publicado

2023-07-06

·

Atualizado

2024-11-19

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 8.8.15 through 9.0
Description An issue in Zimbra Collaboration allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.
Recommendations For versions 8.8.15 and 9.0, consider restricting access to sensitive information and disabling the use of 2FA parameters until a patch is available. As a temporary workaround, avoid using the password parameter in affected API endpoints until the issue is resolved.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29381

Produtos afetados

Zimbra Collaboration