Zimbra Collaboration
cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*
- < 9.0.0 Patch 43
- < 10.0.12
- < 10.1.4
A server-side request forgery (SSRF) vulnerability has been identified in the RSS feed parser of Zimbra Collaboration. This vulnerability is present in version 9.0.0 prior to Patch 43, as well as in the 10.0.x and 10.1.x versions prior to their respective patch releases. The vulnerability allows unauthorized redirection to internal network endpoints.
Exploitation of this vulnerability could lead to unauthorized access to internal network services, potentially allowing for further attacks or data exfiltration.
Users can upgrade to Zimbra Collaboration 9.0.0 Patch 43, 10.0.12, or 10.1.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.