CRITICAL
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd
Published May 29, 2019
9.8
CRITICALCVSS 3.0
EPSS 2.25%
Description
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.
Affected products
No data.
OR
- ≥ 8.7.0 · < 8.7.11
- ≥ 8.8.0 · < 8.8.9
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.7.11
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.9
- 8.8.10
- 8.8.10
- 8.8.10
- 8.8.10
- 8.8.11
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://bugzilla.zimbra.com/show_bug.cgi?id=109093 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12729 Advisory
- https://wiki.zimbra.com/wiki/Security_Center x_refsource_MISCRelease NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.zimbra.com/show_bug.cgi?id=109093 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12729 | Advisory | |
| https://wiki.zimbra.com/wiki/Security_Center | x_refsource_MISCRelease NotesVendor Advisory | |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 29, 2019
Updated Aug 5, 2024
Reserved Dec 15, 2018
Link CVE-2018-20160
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data