SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 47
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
|
— |
9.0.0
|
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
|
10.0.0
|
10.0.12
|
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
|
10.1.0
|
10.1.4
|
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:-:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p1:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p10:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p11:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p12:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p13:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p14:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p15:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p16:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p17:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p18:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p19:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p2:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p20:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p21:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p22:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p23:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24.1:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p25:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p26:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p27:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p28:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p29:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p3:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p30:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p31:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p32:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p33:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p34:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p35:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p36:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p37:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p38:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p39:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p4:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p40:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p41:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p42:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p5:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p6:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p7:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p8:*:*:*:*:*:*
|
— | — |
|
Synacor Zimbra_Collaboration_Suite
cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p9:*:*:*:*:*:*
|
— | — |