The record
Written from the 1 report below. Nothing here is unsourced.
- Zimbra has released security patches in version 10.1.20 fixing nine vulnerabilities, including a command injection flaw in its SNMP monitoring component and four cross-site scripting issues in the Classic Web Client.
- The update also fixes a mail forwarding restriction bypass, reported by a Rapid7 researcher, that could let authenticated users exfiltrate email despite restrictions.
- None of the flaws have been flagged as actively exploited, but similar XSS bugs in the software have been repeatedly abused in the past.
- Customers are advised to apply the updates to keep their environments secure.
What to watch next
- Whether attackers begin exploiting the XSS or SNMP flaws, given the history of abuse of similar bugs.
- Any additional technical details Zimbra may disclose about the vulnerabilities later.
- How quickly administrators roll out the 10.1.20 update to their systems.
Coverage1
1 report
English national1
All filed from India
Named India · Jonah Burgess · Rapid7 · Zimbra
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
