Zimbra Collaboration Server-Side Request Forgery Vulnerability in RSS Feed Parser

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the RSS feed parser of Zimbra Collaboration. This vulnerability is present in version 9.0.0 prior to Patch 43, as well as in the 10.0.x and 10.1.x versions prior to their respective patch releases. The vulnerability allows unauthorized redirection to internal network endpoints.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal network services, potentially allowing for further attacks or data exfiltration.

Remediation

Users can upgrade to Zimbra Collaboration 9.0.0 Patch 43, 10.0.12, or 10.1.4 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
3.1
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.