🔙 목록으로 돌아가기

CVE-2022-41352: Zimbra Collaboration - Unrestricted File Upload

TitleZimbra Collaboration - Unrestricted File Upload
Authorrxerium
SeverityCritical
ImpactUnauthenticated attackers can upload arbitrary files through amavis via a cpio loophole that extracts to the webapps directory, potentially achieving remote code execution and unauthorized access to other user accounts in Zimbra Collaboration Suite.
RemediationInstall pax package and ensure amavis is configured to use pax instead of cpio. Update to the latest patched version of Zimbra Collaboration Suite.
CVSS Score9.8
EPSS Score0.93958
CVE IDCVE-2022-41352
CWE IDCWE-22
Shodan Queryhttp.favicon.hash:"1624375939"http.html:"Zimbra Collaboration Suite Web Client"
Fofa Queryicon_hash="1624375939"
Tags cve cve2022 zimbra kev file-upload passive vkev vuln

🔍 Vulnerability Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

🌐 HTTP Request

GET /js/zimbraMail/share/model/ZmSettings.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-41352.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-41352.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A