CVE-2022-37042

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-37042
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37042.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-37042
Published
2022-08-12T15:15:16.053Z
Modified
2025-12-11T02:04:23.842902Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

References

Affected packages

Git

github.com/zimbra/zm-build

Affected versions

8.*

8.7.10
8.7.11
8.7.6
8.7.7
8.7.9
8.8.0.beta1
8.8.10
8.8.11
8.8.11.p3
8.8.12
8.8.15
8.8.15.p3
8.8.15.p5
8.8.2
8.8.3
8.8.4
8.8.6
8.8.7
8.8.8
8.8.9
8.8.9.p1
8.8.9.p3

9.*

9.0.0
9.0.0.p4

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37042.json"

github.com/zimbra/zm-mailbox

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-mailbox
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected

Affected versions

8.*

8.7.10
8.7.11
8.7.6
8.7.7
8.7.9
8.8.0.beta1
8.8.10
8.8.11
8.8.12
8.8.15
8.8.15.p1
8.8.15.p10
8.8.15.p11
8.8.15.p12
8.8.15.p13
8.8.15.p14
8.8.15.p15
8.8.15.p16
8.8.15.p17
8.8.15.p18
8.8.15.p2
8.8.15.p20
8.8.15.p23
8.8.15.p24
8.8.15.p25
8.8.15.p26
8.8.15.p27
8.8.15.p29
8.8.15.p3
8.8.15.p30
8.8.15.p31
8.8.15.p4
8.8.15.p5
8.8.15.p6
8.8.15.p7
8.8.15.p8
8.8.15.p9
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9

9.*

9.0.0
9.0.0.p1
9.0.0.p10
9.0.0.p11
9.0.0.p13
9.0.0.p14
9.0.0.p16
9.0.0.p18
9.0.0.p19
9.0.0.p2
9.0.0.p20
9.0.0.p22
9.0.0.p23
9.0.0.p3
9.0.0.p4
9.0.0.p5
9.0.0.p6
9.0.0.p7
9.0.0.p8
9.0.0.p9

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37042.json"

github.com/zimbra/zm-zcs

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-zcs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected

Affected versions

8.*

8.7.10
8.7.11
8.7.6
8.7.7
8.7.9
8.8.0.beta1
8.8.0beta2
8.8.10
8.8.11
8.8.12
8.8.15
8.8.15.p6
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37042.json"

github.com/zimbra/zm-zcs-lib

Affected versions

8.*

8.7.10
8.7.11
8.7.6
8.7.7
8.7.9
8.8.0.beta1
8.8.10
8.8.11
8.8.12
8.8.15
8.8.15.p3
8.8.15.p5
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9

9.*

9.0.0

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37042.json"