PT-2022-4906 · Zimbra · Zimbra Collaboration

Yeak Nai Siew

·

Published

2022-09-07

·

Updated

2026-01-10

·

CVE-2022-41352

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 8.8.15 and 9.0
Description An issue exists in Zimbra Collaboration (ZCS) that allows an attacker to upload arbitrary files through amavis via a cpio loophole. This loophole involves extracting files to the /opt/zimbra/jetty/webapps/zimbra/public directory, potentially leading to unauthorized access to other user accounts. Reports indicate ongoing exploitation of this issue in the wild. The vulnerability stems from the use of the cpio archiving utility, and Zimbra recommends using pax instead. While pax is a prerequisite for Zimbra on Ubuntu, it is not a default installation on Red Hat Enterprise Linux (RHEL) or CentOS versions 6 and later. Once installed, amavis automatically prioritizes pax over cpio.
Recommendations For Zimbra Collaboration (ZCS) version 8.8.15, install pax to replace cpio as the preferred archiving utility. For Zimbra Collaboration (ZCS) version 9.0, install pax to replace cpio as the preferred archiving utility.

Exploit

Fix

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2022-06069
CVE-2022-41352

Affected Products

Zimbra Collaboration