← Back

CVE-2020-10194

nvd nist
Published: Mar 20, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.

Affected (9)

Products: Zimbra: Zm Mailbox
1 product
Zm Mailbox
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Zimbra
Before 8.8.15
Version 8.8.15
Version 8.8.15 patch1
Version 8.8.15 patch2
Version 8.8.15 patch3
Version 8.8.15 patch4
Version 8.8.15 patch5
Version 8.8.15 patch6
Version 8.8.15 patch7

References (6)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.