Executive brief
Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform, contains a security flaw in its proxy component. An attacker can exploit this to force the server to make unauthorized requests to internal or external systems, potentially leading to the exposure of sensitive internal data. This vulnerability has been observed being used in active attacks.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the ProxyServlet component of Synacor Zimbra Collaboration Suite (ZCS). The flaw allows a remote, unauthenticated attacker to send specially crafted requests that the server will then forward to other internal or external services. This can be used to bypass network segmentation, access internal-only metadata services, or facilitate further attacks such as remote code execution when combined with other vulnerabilities. The issue is resolved in 8.6 Patch 13, 8.7.11 Patch 10, 8.8.10 Patch 7, and 8.8.11 Patch 3.
Affected products
- Synacor Zimbra Collaboration Suite Before 8.6 Patch 13, 8.7.x before 8.7.11 Patch 10, 8.8.x before 8.8.10 Patch 7, and 8.8.x before 8.8.11 Patch 3
Timeline
- 2019-03-01: advisory: Initial vendor advisory published
- 2025-07-07: kev added: Added to CISA Known Exploited Vulnerabilities catalog