| Title | Zimbra Collaboration - Unrestricted File Upload |
|---|---|
| Author | rxerium |
| Severity | Critical |
| Impact | Unauthenticated attackers can upload arbitrary files through amavis via a cpio loophole that extracts to the webapps directory, potentially achieving remote code execution and unauthorized access to other user accounts in Zimbra Collaboration Suite. |
| Remediation | Install pax package and ensure amavis is configured to use pax instead of cpio. Update to the latest patched version of Zimbra Collaboration Suite. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93958 |
| CVE ID | CVE-2022-41352 |
| CWE ID | CWE-22 |
| Shodan Query | http.favicon.hash:"1624375939"http.html:"Zimbra Collaboration Suite Web Client" |
| Fofa Query | icon_hash="1624375939" |
| Tags | cve cve2022 zimbra kev file-upload passive vkev vuln |
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
GET /js/zimbraMail/share/model/ZmSettings.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-41352.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-41352.pcap
N/AN/A