Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-37041
HistoryAug 12, 2022 - 3:15 p.m.

Design/Logic Flaw

2022-08-1215:15:00
PRIOn knowledge base
www.prio-n.com
4

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.5%

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).

CPENameOperatorVersion
collaborationeq9.0.0
collaborationeq8.8.15

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.5%

Related for PRION:CVE-2022-37041