Description
A component of Zimbra Collaboration Suite allows an unauthenticated attacker to send an HTTP request to a remote host. An attacker may use this feature to perform SSRF (Server-side request forgery) attacks on the server.
Remediation
Upgrade to the latest version of Zimbra Collaboration Suite
References
Related Vulnerabilities
Kentico CMS Deserialization RCE
WordPress Plugin Web Stories Server-Side Request Forgery (1.24.0)
Oracle Business Intelligence AMF Deserialization RCE CVE-2020-2950
TorchServe Management API SSRF (CVE-2023-43654)
WordPress Plugin GiveWP-Donation and Fundraising Platform Multiple Vulnerabilities (2.25.1)