← Back

CVE-2021-34807

nvd nist
Published: Jul 2, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could redirect a user to any URL via isredirect=1&redirectURL= in conjunction with the token data (e.g., a valid authtoken= value).

Affected (40)

1 product
Collaboration
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Zimbra
Before 8.8.15
Version 8.8.15
Version 8.8.15 p10
Version 8.8.15 p11
Version 8.8.15 p12
Version 8.8.15 p13
Version 8.8.15 p14
Version 8.8.15 p15
Version 8.8.15 p16
Version 8.8.15 p17
Version 8.8.15 p18
Version 8.8.15 p19
Version 8.8.15 p1
Version 8.8.15 p20
Version 8.8.15 p21
Version 8.8.15 p22
Version 8.8.15 p2
Version 8.8.15 p3
Version 8.8.15 p4
Version 8.8.15 p5
Version 8.8.15 p6
Version 8.8.15 p7
Version 8.8.15 p8
Version 8.8.15 p9
Version 9.0.0
Version 9.0.0 p10
Version 9.0.0 p11
Version 9.0.0 p12
Version 9.0.0 p13
Version 9.0.0 p14
Version 9.0.0 p15
Version 9.0.0 p1
Version 9.0.0 p2
Version 9.0.0 p3
Version 9.0.0 p4
Version 9.0.0 p5
Version 9.0.0 p6
Version 9.0.0 p7
Version 9.0.0 p8
Version 9.0.0 p9

References (8)

Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.