Description
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Vector
- network
- Complexity
- low
- Privileges
- low
- User Action
- none
- Scope
- unchanged
- Confidentiality
- none
- Integrity
- high
- Availability
- none
- Weaknesses
- CWE-862
Metadata
- Primary Vendor
- ZIMBRA
- Published
- 3/20/2020
- Last Modified
- 11/21/2024
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
zimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailboxzimbra : zm-mailbox
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.