SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
History

Thu, 13 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 18 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 04 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 19:30:00 +0000

Type Values Removed Values Added
Description SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-02-03T00:00:00.000Z

Updated: 2025-03-13T20:47:30.615Z

Reserved: 2025-02-03T00:00:00.000Z

Link: CVE-2025-25065

cve-icon Vulnrichment

Updated: 2025-02-04T15:49:11.040Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-03T20:15:37.370

Modified: 2025-03-13T21:15:43.613

Link: CVE-2025-25065

cve-icon Redhat

No data.