An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavisd automatically prefers it over cpio.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
kingslyj | https://nvd.nist.gov/vuln/detail/CVE-2022-41352 | Source kingslyj 1631795395650285568 | 2023/03/04 |
HiveProInc | https://www.hivepro.com/a-new-rorschach-ransomware-threat-e... | Source HiveProInc 1646074300066086918 | 2023/04/12 |
HiveProInc | https://twitter.com/HiveProInc/status/1646074300066086918/p... | Source HiveProInc 1646074300066086918 | 2023/04/12 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
cvetrends.com | 51 |
twinybots.ch | 37 |
lists.astaro.com | 12 |
www.helpnetsecurity.com | 11 |
thehackernews.com | 8 |
securelist.com | 7 |
securityaffairs.co | 7 |
attackerkb.com | 6 |
tweetedtimes.com | 5 |
github.com | 4 |
www.rapid7.com | 4 |
t.me | 3 |
kas.pr | 3 |
zpr.io | 3 |
buff.ly | 3 |
twitter.com | 3 |
wiki.zimbra.com | 3 |
latam.kaspersky.com | 3 |
blog.segu-info.com.ar | 3 |
www.itsecuritynews.info | 3 |
User | URL | Info Source |
---|---|---|
kingslyj | nvd.nist.gov | Show Tweet |
HiveProInc | hivepro.com | Show Tweet |
HiveProInc | twitter.com | Show Tweet |
Name | URL |
---|---|
segfault-it/cve-2022-41352 | https://github.com/segfault-it/cve-2022-41352 |
Cr4ckC4t/cve-2022-41352-zimbra-rce | https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce |
Name | URL |
---|---|
segfault-it/cve-2022-41352 | github.com |
Cr4ckC4t/cve-2022-41352-zimbra-rce | github.com |