Aller au contenu

Fiche vulnérabilité

CVE-2022-41347 : faille élevée zimbra collaboration (CVSS 7.8)

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 sept. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • zimbra collaboration

Références

Rechercher une autre vulnérabilité dans la base CVE