Lucene search

K
cvelistMitreCVELIST:CVE-2022-37041
HistoryAug 11, 2022 - 7:06 p.m.

CVE-2022-37041

2022-08-1119:06:49
mitre
www.cve.org
1

8.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).

8.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

Related for CVELIST:CVE-2022-37041