CVE-2022-41347
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Se ha detectado un problema en Zimbra Collaboration (ZCS) versiones 8.8.x y 9.x (por ejemplo, 8.8.15). La configuración Sudo permite al usuario zimbra ejecutar el binario NGINX como root con parámetros arbitrarios. Como parte de su funcionalidad prevista, NGINX puede cargar un archivo de configuración definido por el usuario, que incluye plugins en forma de archivos .so, que también son ejecutados como root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-26 CVE Reserved
- 2022-09-26 CVE Published
- 2024-05-17 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/darrenmartyn/zimbra-hinginx | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://darrenmartyn.ie/2021/10/25/zimbra-nginx-local-root-exploit | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://wiki.zimbra.com/wiki/Security_Center | 2022-09-28 |
URL | Date | SRC |
---|---|---|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | 2022-09-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 8.8.15 Search vendor "Zimbra" for product "Collaboration" and version "8.8.15" | - |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | - |
Affected
|