THREATOPS
THREAT OPSThreat News › [NVD] CVE-2022-41352 (CRITICAL 9.8) — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends

[NVD] CVE-2022-41352 (CRITICAL 9.8) — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends

lownvdPublished 2022-09-26

CVE-2022-41352 CVSS: 9.8 CRITICAL Published: 2022-09-26T02:15:10.733

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites o

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-41352