Zimbra's November 2025 security release
You could manually check this page:
ZCS 10.1.19 was released on Tue Jul 07 2026. The release includes security fixes for:
ZCS 10.1.18 was released on Tue Jun 16 2026. The release includes security fixes for:
ZCS 10.1.17 was released on Thu May 28 2026. The release includes security fixes for:
ZCS 10.1.16 was released on Wed Feb 04 2026. The release includes security fixes for:
ZCS 10.1.13 was released on Thu Nov 06 2025. The release includes security fixes for:
ZCS 10.0.18 was released on Thu Nov 06 2025. The release includes security fixes for:
ZCS 10.1.12 was released on Thu Oct 16 2025. The release includes security fixes for:
ZCS 10.1.10 was released on Fri July 18 2025. The release includes security fixes for:
ZCS 10.0.16 was released on Fri July 18 2025. The release includes security fixes for:
ZCS 10.1.9 was released on Wed June 18 2025. The release includes security fixes for:
ZCS 10.0.15 was released on Wed June 18 2025. The release includes security fixes for:
ZCS 9.0.0 Patch 46 was released on Wed June 18 2025. The release includes security fixes for:
ZCS 10.1.8 was released on Thu May 15 2025. The release includes security fixes for:
ZCS 10.0.14 was released on Thu May 15 2025. The release includes security fixes for:
ZCS 9.0.0 Patch 45 was released on Thu May 15 2025. The release includes security fixes for:
ZCS 10.1.6 was released on Mon Mar 03 2025. The release includes security fixes for:
ZCS 10.1.5 was released on Mon Jan 27 2025. The release includes security fixes for:
ZCS 10.0.13 was released on Mon Jan 27 2025. The release includes security fixes for:
ZCS 9.0.0 Patch 44 was released on Mon Jan 27 2025. The release includes security fixes for:
ZCS 10.1.4 was released on Tue Dec 17 2024. The release includes security fixes for:
ZCS 10.0.12 was released on Tue Dec 17 2024. The release includes security fixes for:
ZCS 9.0.0 Patch 43 was released on Tue Dec 17 2024. The release includes security fixes for:
ZCS 8.8.15 Patch 47 was released on Tue Dec 17 2024. The release includes security fixes for:
ZCS 10.1.3 was released on Tue Nov 12 2024. The release includes security fixes for:
ZCS 10.0.11 was released on Tue Nov 12 2024. The release includes security fixes for:
ZCS 10.1.2 was released on Tue Oct 08 2024. The release includes security fixes for:
ZCS 10.0.10 was released on Tue Oct 08 2024. The release includes security fixes for:
ZCS 9.0.0 Patch 42 was released on Tue Oct 08 2024. The release includes security fixes for:
ZCS 10.1.1 was released on Wed Sep 04 2024. The release includes security fixes for:
ZCS 10.0.9 was released on Wed Sep 04 2024. The release includes security fixes for:
ZCS 9.0.0 Patch 41 was released on Wed Sep 04 2024. The release includes security fixes for:
ZCS 8.8.15 Patch 46 was released on Wed Sep 04 2024. The release includes security fixes for:
ZCS 10.1.1 was released on Wed Sep 04 2024. The release includes security fixes for:
ZCS 10.1.0 was released on Tue Jul 16 2024. The release includes security fixes for:
ZCS 10.0.8 was released on Mon Apr 22 2024. The release includes security fixes for:
ZCS 9.0.0 Patch 40 was released on Mon Apr 22 2024. The release includes security fixes for:
ZCS 10.0.7 was released on Wed Feb 28 2024. The release includes security fixes for:
ZCS 9.0.0 Patch 39 was released on Wed Feb 28 2024. The release includes security fixes for:
ZCS 10.0.6 was released on Mon Dec 18 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 38 was released on Mon Dec 18 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 45 was released on Mon Dec 18 2023. The release includes security fixes for:
ZCS 10.0.5 was released on Thu Oct 19 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 37 was released on Thu Oct 19 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 44 was released on Thu Oct 19 2023. The release includes security fixes for:
ZCS 10.0.4 was released on Wed Sep 13 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 36 was released on Wed Sep 13 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 43 was released on Wed Sep 13 2023. The release includes security fixes for:
ZCS 10.0.3 was released on Wed Aug 23 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 35 was released on Wed Aug 23 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 42 was released on Wed Aug 23 2023. The release includes security fixes for:
ZCS 10.0.2 was released on Wed Jul 26 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 34 was released on Wed Jul 26 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 41 was released on Wed Jul 26 2023. The release includes security fixes for:
Daffodil 10.0.1 was released on Tue May 30 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 33 was released on Tue May 30 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 40 was released on Tue May 30 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 31 was released on March 2, 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 38 was released on March 2, 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 30 was released on February 21, 2023. The release includes security fixes for:
ZCS 8.8.15 Patch 37 was released on February 21, 2023. The release includes security fixes for:
ZCS 9.0.0 Patch 28 was released on November 21, 2022. The release includes security fixes for:
ZCS 8.8.15 Patch 35 was released on November 21, 2022. The release includes security fixes for:
ZCS 9.0.0 Patch 27 was released on October 11, 2022. The release includes security fixes for:
ZCS 8.8.15 Patch 34 was released on October 11, 2022. The release includes security fixes for:
ZCS 9.0.0 Patch 26 was released on July 28, 2022. The release includes security fixes for:
ZCS 8.8.15 Patch 33 was released on July 28, 2022. The release includes security fixes for:
ZCS 9.0.0 Patch 25 was released on June 14, 2022. The release includes security fixes for:
ZCS 8.8.15 Patch 32 was released on June 14, 2022. The release includes security fixes for:
ZCS 9.0.0 Patch 24.1 was released on May 10, 2022. The release includes security fixes for:
ZCS 8.8.15 Patch 31.1 was released on May 10, 2022. The release includes security fixes for:
ZCS 9.0.0 Patch 24 was released on March 30, 2022. The release includes security fixes for:
Spring4Shell security hotfix was released in Patch 24 on April 21, 2022:
ZCS 8.8.15 Patch 31 was released on March 30, 2022. The release includes security fixes for:
A Security Hotfix for ZCS 8.8.15 Patch 30 was released on February 05, 2022. The hotfix release includes security fix for:
ZCS 9.0.0 Patch 21 was released on November 22, 2021. The release includes security fixes for:
ZCS 8.8.15 Patch 28 was released on November 22, 2021. The release includes security fixes for:
ZCS 9.0.0 Patch 20 was released on October 25, 2021. The release includes security fixes for:
ZCS 8.8.15 Patch 27 was released on October 25, 2021. The release includes security fixes for:
ZCS 9.0.0 Patch 16 was released on July 28, 2021. The release includes security fixes for:
ZCS 9.0.0 Patch 10 was released on December 16, 2020. The release includes security fixes for:
ZCS 8.8.15 Patch 17 was released on December 16, 2020. The release includes security fixes for:
ZCS 9.0.0 Patch 5 was released on July 27, 2020. The release includes security fixes for:
ZCS 9.0.0 Patch 4 and ZCS 8.8.15 Patch 11 were released on July 2, 2020. The release includes security fixes for:
ZCS 9.0.0 Patch 3 and ZCS 8.8.15 Patch 10 were released on June 3, 2020. The release includes security fixes for:
ZCS Patch 2 was released on May 4, 2020. The release includes security fixes for:
ZCS Patch 9 was released on April 23, 2020. The release includes security fixes for:
ZCS Patch 8 was released on March 9, 2020. The release includes security fixes for:
ZCS Patch 7 was released on Feb 10, 2020. The release includes security fixes for:
ZCS Patch 2 was released on September 30, 2019. The release includes security fixes for:
ZCS 8.8.15 Patch 1 was released on August 28, 2019. The release includes security fixes for:
September 6, 2019 - Phil Pearl , Security Architect
ZCS 8.7.11 Patch 11 , 8.8.9 Patch 10 , 8.8.10 Patch 8 and 8.8.11 Patch 4 were released on April 15, 2019. The releases includes security fixes for:
8.8.9 Patch 10 , adds one additional security fix (which is already included in earlier updates of the other releases mentioned above):
ZCS 8.8.12 Patch 1 was also released on April 15, 2019. The fixes mentioned above were in the initial release for 8.8.12, but this patch adds one additional security fix:
April 15, 2019 - Phil Pearl , Security Architect
ZCS 8.8.12 was released on April 1, 2019 . The release includes security fixes for:
April 3, 2019 - Phil Pearl , Security Architect
We published a blog post regarding recent Zimbra XXE / SSRF vulnerabilities disclosed by An Phuoc Trinh , of Viettel Cyber Security. In short:
See the blog post for a few additional details: Recent Zimbra XXE / SSRF Vulnerability Disclosure .
Updated: March 19, 2019 - Phil Pearl , Security Architect March 18, 2019 - Phil Pearl , Security Architect
ZCS 8.7.11 Patch 10 was released on March 18, 2019 and 8.6.0 Patch 13 was released on March 19, 2019. The releases includes security fixes for (8.8.x versions are not affected by this vulnerability):
Updated: March 19, 2019 - Phil Pearl , Security Architect March 18, 2019 - Phil Pearl , Security Architect
ZCS 8.7.11 Patch 9 , 8.8.10 Patch 7 and 8.8.11 Patch 3 were released on March 4, 2019. The releases includes security fixes for:
A special thanks to An Phuoc Trinh , of Viettel Cyber Security, who has been going the extra mile to report his findings to us. His efforts are greatly appreciated! Please note, the rating has been upgraded to " major " as the original scoring did not cover all potential available attack vectors.
Updated: March 8, 2019 - Phil Pearl , Security Architect March 4, 2019 - Phil Pearl , Security Architect
ZCS 8.7.11 Patch 8 was released February 1, 2019. The release includes security fixes for:
February 1, 2019 - Phil Pearl , Security Architect
ZCS 8.8.9 Patch 9 , ZCS 8.8.10 Patch 5 and ZCS 8.8.11 Patch 1 were released January 4, 2019. The releases include security fixes for:
January 4, 2019 - Phil Pearl , Security Architect
ZCS 8.8.11 was released December 17, 2018. The release includes a fix for a non-persistent XSS CVE-2018-14013 / bug 109017 ( CWE 79 ).
December 17, 2018 - Phil Pearl , Security Architect
ZCS 8.8.9 P7 was released November 6, 2018. The patch includes a fix for a persistent XSS CVE-2018-18631 / bug 109020 ( CWE 79 ).
November 7, 2018 - Phil Pearl , Security Architect
ZCS 8.8.10 P2 and ZCS 8.7.11 P7 were released October 29, 2018. Both patches include a fix for a persistent XSS CVE-2018-18631 / bug 109020 ( CWE 79 ). ZCS 8.7.11 P7 also includes a fix (already in ZCS 8.8.10 P1) for a non-persistent XSS CVE-2018-14013 / bug 109018 ( CWE 79 ). Please note, there is a second non-persistent XSS ( bug 109017 ), also part of CVE-2018-14013, which is not fixed in this patch set.
October 29, 2018 - Phil Pearl , Security Architect
ZCS 8.8.10 P1 and ZCS 8.8.9 P6 were released October 17, 2018. They include a fix for a non-persistent XSS CVE-2018-14013 / bug 109018 ( CWE 79 ). Please note, there is a second non-persistent XSS ( bug 109017 ), also part of CVE-2018-14013, which is not fixed in this patch set.
October 17, 2018 - Phil Pearl , Security Architect
ZCS 8.8.10 was released October 2, 2018. It includes a fix for a limited text content injection vulnerability CVE-2018-17938 / bug 109021 ( CWE 345 ).
October 2, 2018 - Phil Pearl , Security Architect
ZCS 8.8.8 Patch9 was released August 30, 2018. It includes a fix for an Account Enumeration vulnerability, CVE-2018-15131 / bug 109012 .
August 31, 2018 - Phil Pearl , Security Architect
ZCS 8.8.9 Patch3 and ZCS 8.7.11 Patch6 were released August 17, 2018. They include a fix for an Account Enumeration vulnerability, CVE-2018-15131 / bug 109012 .
ZCS 8.6.0 Patch11 was released August 17, 2018. This includes fixes for 11 vulnerabilities. See the release notes for details.
Updated: Aug 21, 2018 - Phil Pearl , Security Architect Aug 19, 2018 - Phil Pearl , Security Architect
ZCS 8.8.8 Patch7 and ZCS 8.8.9 Patch1 were released July 19, 2018. They include a fix for a Persistent XSS vulnerability, CVE-2018-14425 / bug 108970 .
July 24, 2018 - Phil Pearl , Security Architect
ZCS 8.8.8 Patch4 and ZCS 8.7.11 Patch4 were released May 24, 2018. They include a fix for a XSS vulnerability, CVE-2018-10939 / bug 108902 .
May 24, 2018 - Phil Pearl , Security Architect
ZCS 8.8.8 Patch1 and ZCS 8.7.11 Patch2 were released April 12, 2018. They include a fix for a CSRF vulnerability, CVE-2015-7610 / bug 97579 .
Apr 14, 2018 - Phil Pearl , Security Architect
ZCS 8.7.11 Patch1 was released March 14, 2018. This includes a fix for three XSS vulnerabilities, CVE-2017-17703 / bug 108265 , CVE-2017-8802 / bug 107925 , and CVE-2018-6882 / bug 108786 .
Apr 14, 2018 - Phil Pearl , Security Architect
ZCS 8.8.7 was released today. It includes fixes for a Persistent XSS vulnerability, CVE-2018-6882 / bug 108768 and Mailsploit related issues / bug 108709 .
Note: We recommend that all sites upgrading to 8.8.7 manually set zimbraPrefShortEmailAddress to FALSE which is the default for new 8.8.7 installs.
Mar 8, 2018 - Phil Pearl , Security Architect
ZCS 8.6.0 Patch 9 was released today and includes fixes for two Persistent XSS vulnerabilities, CVE-2017-8802 / bug 107925 and CVE-2017-17703 / bug 108265 .
If this patch is not applied, one potential workaround to avoid this issue is to set zimbraPrefUseKeyboardShortcuts to FALSE (for all users/classes-of-service). Note: disabling keyboard shortcuts would have the side effect of disabling all ZCS controlled keyboard shortcuts and this may impact normal user client interaction.
Feb 9, 2018 - Phil Pearl , Security Architect
All supported versions of Zimbra Web Client (ZWC) prior to 8.8.7 are affected by Mailsploit . We recommend that all sites upgrading to 8.8.7 manually set zimbraPrefShortEmailAddress to FALSE which is the default for new 8.8.7 installs.
The workaround which addresses most issues is to set zimbraPrefShortEmailAddress to FALSE (if you are an administrator) for all users/classes-of-service. As an end user you can also control this setting by going to 'Preferences > Display names in place of email addresses when available' and deselecting the checkbox for this option (this is the end user control for the preference attribute mentioned above). This issue is being tracked as bug 108709 .
Update 8.8.7 released: Mar 8, 2018 - Phil Pearl , Security Architect
Dec 11, 2017 - Phil Pearl , Security Architect
The following vulnerabilities were fixed in ZCS 8.7.10:
Thank you to Stephan Kaag of Securify for reporting bug 107878!
May 24, 2017 - Phil Pearl , Security Architect
The following vulnerabilities were fixed in ZCS 8.7.6:
March 30, 2017 - Phil Pearl , Security Architect
A fix for a limited capability XXE - CVE-2016-9924 / bug 106811 is included in release ZCS 8.7.4. This issue affects all supported versions of ZCS before 8.7.4.
A special thanks to Alastair Gray for taking the time to report this issue!
March 1, 2017 - Phil Pearl , Security Architect
The details of CVE-2016-3403 / bug 100899 (see also bug 100885 ) were publicly disclosed by Sysdream Labs on 2017-01-11.
Please note the fixes for the flaws were included as part of ZCS 8.7.0, which was released on 2016-07-13 .
Thank you to Sysdream for your assistance and cooperation!
January 11, 2017 - Phil Pearl , Security Architect
Lawrence Abrams of Bleeping Computer has reported that there is a new ransomware variant , written in Python, that is targeting ZCS server data under /opt/zimbra/store/ .
At this point, no details have been provided how any servers were compromised. Without any details, the best advice we can give is:
June 22, 2016 - Phil Pearl , Security Architect
The 2016-05-03 announcement by OpenSSL regarding a padding oracle in the AES-NI CBC MAC check affects supported releases of ZCS 8.0-8.6.0 (via MTAs and Proxy).
We anticipate releasing 8.6.1 (and 8.7) with fixes for this issue, however if this issue is impacting your environment, the recommended workaround is covered in bug 104982 . NOTE: in ZCS 8.7+ we are able to easily patch third party packages included with ZCS via package repos .
First, test that you are vulnerable with the following tool:
A special thanks to Malte Stretz from our Gold Partner, Silpion , for his persistence and hard work to gather the information covered in this workaround! Also this article would be incomplete without mentioning that the original inspiration for this workaround came from .
Jun 14, 2016 - Phil Pearl , Security Architect
The 2016-03-01 announcement by OpenSSL regarding DROWN via SSLv2 affects ZCS 8.0.x (via MTAs), but no other currently supported releases . See How to disable SSLv3 , as it includes instructions on disabling SSLv2 and SSLv3. Additional info may also be found in bug 104130 .
Mar 01, 2016 - Phil Pearl , Security Architect
ZCS 8.6.0 Patch 5 is available (officially released Dec 21, 2015). Patch 5 includes fixes for five (5) CVE's (ref: Zimbra Security Advisories ). Three of the CVE-IDs referenced in the patch come via 3rd party components shipped w/ZCS. Please note, one of the fixed vulnerabilities is rated as major . See the blog post or the release notes (available from the downloads area for additional notes on ZCS 8.6.0 Patch 5.
[Update: Feb 2, 2016] If you can not patch immediately, the XSS bug classified as major (bug 101435) can be worked around by either disabling or uninstalling (zmzimletctl undeploy) the com_zimbra_url (aka URL links) zimlet.
Dec 23, 2015 - Phil Pearl , Security Architect
Today's announcement by OpenSSL ( ) regarding alternative chains certificate forgery does not affect any Zimbra Collaboration releases. Specifically, the latest Zimbra Collaboration 8.6 release ships with OpenSSL 1.0.1l, but this issue affects the following OpenSSL versions 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o only.
Jul 09, 2015 - Phil Pearl , Security Architect
There is a lot of chatter Logjam - today.
At this time, the initial impacts to Collab seem to be minimal and are currently limited to the MTA, specifically possible setting changes, depending upon your environment.
Today we updated the MTA Ciphers section of our Collab 8.6 security wiki page. In short, for anyone concerned the Logjam (cipher downgrade) style of MitM attacks, the use of 'export' and 'low' ciphers in Postfix should be avoided. Please note that Postfix, by default ( ) allows use of lower ciphers. Changing these to 'medium' can reduce client interoperability and/or may cause some clients to fall back to in the clear communication channels instead of using lower grade encryption.
As usual, there are trade-offs involved, but in the light of FREAK ( ) and Logjam ( ) attacks, it may also be argued that using ciphers lower than 'medium' is now potentially providing an illusion of security. With this in mind, our current recommendation is to avoid both 'export' and 'low' ciphers with the hope that complete deprecation of these ciphers will be coming soon.
Please visit to keep up with our latest recommendations. Also, for those looking to strengthen their security posture, in Collab 8.7 we have a number of enhancements slated including the ability to strengthen DH params . A sneak preview of security related changes/enhancements in the works is available at .
Lastly, for those with openssl 1.0.2 available, you may find this post from OpenSSL useful
Update for 8.0.x customers : In Collab 8.0.x, Java 1.7 is used. Unfortunately, in Java 1.7, the DH parameters are hard-coded to 768 bits (excluding when using export cipher suites, which use 512 bits, but those should already be disabled). The workaround is to use the (Nginx) Proxy always. The other option is to disable all DHE suites. Which has the side effect of losing forward secrecy for any user agents that do not support ECDHE. (ref:
May 28, 2015 - Phil Pearl , Security Architect
Zimbra is aware of a newly disclosed SSL/TLS vulnerability that provides a potential malicious actor with a method to perform a Man-in-the-Middle (MitM) attack the vulnerability is being referred to as FREAK (Factoring attack on RSA-EXPORT Keys), utilizing CVE-2015-0204 .
The attack allows a malicious actor to force a downgrade of a secure connection to a vulnerable, export grade encryption (READ: weak encryption). Which, according to Washington Post , is downgraded to 512-bit encryption that was the maximum allowed under the export controls in place during the 1990s in the U.S. The Washington Post piece goes on to say it is possible to crack 512-bit encryption, today, in approximately 7 hours with the use of 75 computers, which can be rented from a cloud computing provider for approximately $100.
Matthew Green , cryptographer and research professor from Johns Hopkins, provided a Cliffs Notes version:
A group of cryptographers at INRIA, Microsoft Research and IMDEA have discovered some serious vulnerabilities in OpenSSL (e.g., Android) clients and Apple TLS/SSL clients (e.g., Safari) that allow a 'man in the middle attacker' to downgrade connections from 'strong' RSA to 'export-grade' RSA. These attacks are real and exploitable against a shocking number of websites -- including government websites. Patch soon and be careful.
In addition to Matthew Green's post and the Washington Post article, the freakattack.com site has additional information, including a list of the top domains still vulnerable, as well as a built in check of the browser used to surf to the site.
Zimbra ships with the OpenSSL library. At this time, Zimbra has assessed Zimbra Collaboration 8.x, 7.x and found no susceptibility to the FREAK attack in the servers. As there is a client side component to this attack, please verify that you are running the latest browsers/clients to lower the risk to this type of attack.
As part of our security program, Zimbra will continue to monitor all developments related to the FREAK vulnerability and update this post as needed.
Mar 05, 2015 - Phil Pearl , Security Architect
Zimbra is aware of a Linux vulnerability, specifically the GNU C Library.
The vulnerability appears to have been found by Qualys and disclosed in security advisory CVE 2015-0235 . It should be noted that the vulnerability was patched in v 2.17 of the library, but at the time was not categorized as a security issue, leading many to maintain stable versions, i.e. vulnerable versions. This is an operating system vulnerability; at this time, and to the best of our knowledge, there are no known exploits against Zimbra's software related to CVE 2015-0235.
Zimbra recommends that anyone running Linux update their systems as soon as possible. And while Linux doesn't usually require a restart, it is recommended to ensure all underlying software services are patched.
Patches or acknowledgements
GNU C Library's upstream Git Ubuntu Debian Red Hat CentOS SUSE
Note: the original post was updated slightly to clarify the relationship between the vulnerability and the lack of known exploits against software shipped by Zimbra.
Jan 28, 2015 - Phil Pearl , Security Architect
We have received a few inquiries the reported TLS protocol vulnerability via the POODLE attack. SSL/TLS services in ZCS come from OpenSSL and Java. This vulnerability does not affect OpenSSL (ref: ) and Java is not known to be affected.
For anyone looking for more information, I recommend you look at by Adam Langley.
Dec 11, 2014 - Phil Pearl , Security Architect
Zimbra Collaboration 8.0.9 and 8.5.1 are out with security updates, including the update to OpenSSL 1.0.1j. For those looking to disable SSLv3 remember to (re)visit .
Find here extra details on the releases:
And, as always, don't forget to read the release notes.
Nov 06, 2014 - Phil Pearl , Security Architect
Zimbra is aware of, and has been closely monitoring, the developments of the Shellshock vulnerability. At this time, Zimbra has found no impact on our products, nor do we anticipate any. We have posted initial information on our main blog. Please head over to for any updates related to this issue.
Sep 25, 2014 - Phil Pearl , Security Architect
Security is top of mind for everyone here at Zimbra, which is why we want to inform you that our team just discovered a security vulnerability in Zimbra Community 8.0 (formerly Telligent Community and Telligent Enterprise). The vulnerability is relegated to a very specific scenario in which a user within Zimbra Community 8.0 is able to view a user password via a specific API call.
Summary: The Zimbra development team has identified a very specific scenario where a user’s password in Community 8 is stored insecurely.
Affected Versions: 8.0.0.37997 (unpatched), 8.0.1.39116
Vulnerability Scoring: CVSS: 1.4
Obtaining a fix:
Details: The administrative feature to create users leverages non-public APIs that can force a user’s password to be inadvertently stored insecurely.
Reporter: Alex Crome (Zimbra)
When does this occur?
1. Creating a user through the control panel using Membership Administration (requires administrative privileges)
2. Could occur if a custom plugin was deployed that copied off the extended attributes on a create user event and in turn re-saved those attributes using the UpdateUser API (this is unlikely, but possible)
If you have any questions or would like assistance with applying the patch, please support .
This advisory was originally published here .
Jul 01, 2014 - Phil Pearl , Security Architect
20140606: Zimbra Security Advisory on CVE-2014-0224 (CCS Injection Vulnerability)
On June 5, 2014 the OpenSSL project released a security advisory . CVE-2014-0224 can allow for a man-in-the-middle (MITM) attack to be carried out between a vulnerable client and vulnerable server. It is also important to note that Zimbra does not use DTLS nor do we have SSL_MODE_RELEASE_BUFFERS enabled.
The impact to Zimbra Collaboration Server is as follows:
Specifically, nginx, postfix and OpenLDAP all link to OpenSSL shipped in ZCS8. Other components in the ZCS package also link to the openssl libraries, but the above three are the potentially Internet-facing services that would be attackable. All versions of ZCS8 as released today are vulnerable. ZCS7 is not vulnerable because it uses OpenSSL 1.0.0, which is not vulnerable.
If you are running a version prior to 8.0.3, your server is susceptible to other critical security vulnerabilities (reference: ). Please upgrade to a newer version first, then run this patch.
Zimbra has produced a patch for OpenSSL vulnerabily for versions 8.0.3 to 8.0.7. The patch downloads the correct and patched version of OpenSSL for the following versions and then installs the new package:
The following patch instructions must be done on a per server basis:
After a successful patch, ZCS 8.0.7 will be running 1.0.1h. To verify this, run the following as zimbra user:
On an 8.0.7 patched system the result should be:
Earlier versions of ZCS will show other versions of OpenSSL - Zimbra patches the existing OpenSSL version appropriate to each ZCS version.
Continue to the server and repeat the patch process.
Internet access from each node is required to run this patch automatically. The patch should be installed on all ZCS nodes, most importantly the proxies, MTAs and LDAP nodes.
Also, please note: if you upgrade to a GA release after patching, you would need to re-patch. For example, if you install this patch on ZCS 8.0.6, then upgrade to ZCS 8.0.7, you would need to re-patch against 8.0.7.
Finally, please note that the various Operating Systems are also vulnerable to this issue. The Zimbra patch will not update OS-level openssl libraries. It only updates the openssl package in /opt/zimbra.
Jun 08, 2014 - Phil Pearl , Security Architect
Zimbra Collaboration Server 8 is susceptible to the OpenSSL Heartbleed bug:
Specifically, nginx, postfix and OpenLDAP all link directly to OpenSSL shipped in ZCS8. Other components in the ZCS package also link to the openssl libraries, but the above three are the potentially Internet-facing services that would be attackable. All versions of ZCS8 as released today are vulnerable. ZCS7 is not vulnerable because it uses OpenSSL 1.0.0, which is not vulnerable. Only OpenSSL 1.0.1 and later are reported as being vulnerable. Zimbra has produced an OpenSSL patch for versions 8.0.3 to 8.0.7. If you are running a version prior to 8.0.3, your server is susceptible to other critical security vulnerabilities (reference: ), so you would please need to upgrade to a secure version first, then run this patch. The patch is located here:
The patch downloads the correct and patched version of OpenSSL for the following versions and then installs the new package:
Internet access from each node is required to run this patch automatically. The patch should be installed on all ZCS nodes, most importantly the proxies, MTAs and LDAP nodes. Please note: this vulnerability is being reported as having existed and actively attacked since 2012. As such, the private SSL keys for your platform may already have been compromised. After patching, it is recommended to regenerate your SSL certificates and private keys. This is unfortunate, but the only way to ensure that an attacker cannot decrypt your SSL session data. Also, please note: if you upgrade to a GA release after patching, you would need to re-patch. For example, if you install this patch on ZCS 8.0.6, then upgrade to ZCS 8.0.7, you would need to re-patch against 8.0.7. Finally, please note that the various Operating Systems are also vulnerable to this issue if running OpenSSL 1.0.1. The Zimbra patch will not update OS-level openssl libraries - it only updates the openssl package in /opt/zimbra. For example:
The steps to patch are the following: (as root) 1) wget 2) chmod a+rx zmopenssl-updater.sh 3) ./zmopenssl-updater.sh --------------------- [Generates the following output] Downloading patched openssl Validating patched openssl: success Backing up old openssl: complete Installing patched openssl: complete OpenSSL patch process complete. Please restart Zimbra Collaboration Suite as the Zimbra user via zmcontrol restart --------------------- (as user zimbra) 4) su - zimbra 5) zmcontrol restart[/CODE]
If you don’t have Internet access, manually installing the patch would require the following steps: 1) Download the appropriate openssl build: (as root) cd /tmp wget the correct version, from this list:
The MD5 files are also available for verification purposes, here:
(as root) 2) cd /opt/zimbra 3) mv openssl-OLDVERSION openssl-OLDVERSION.brokenheart 4) tar xfz /tmp/openssl-NEWVERSION.tgz (as user zimbra) 5) su - zimbra 6) zmcontrol restart
Zimbra Collaboration Suite 8.0.7 - both the Network Edition and Open-Source Edition - have been rebuilt to include the fix for the OpenSSL Heartbleed Vulnerability.
If you haven't yet upgraded to 8.0.7, the current versions up on the Download site now disable TLS Heartbeat and protect against the OpenSSL Heartbleed Vulnerability:
If you patched for the OpenSSL Heartbleed vulnerability for Zimbra Collaboration Server 8.0.3 prior to Wed April 09, 2014, 11:00 Eastern/08:00 Pacific, you will need to re-patch.
Please note: this is ONLY for ZCS 8.0.3. All other patches were fine, but the 8.0.3 openssl builds were still vulnerable. Repeating, this is only for ZCS 8.0.3.
Here is how you can check your build version: $ zmcontrol -v (look for "8.0.3") Please use the test methods below to confirm.
There are a few ways you can confirm if your system is vulnerable:
1. If running ZCS 8.0.7, check your version tarball for the build number 6021. For example:
2. If running ZCS 8.0.7, check zmcontrol for the build number: # su - zimbra $ zmcontrol -v Release 8.0.7_GA_ 6021 .RHEL6_64_20140408123937 RHEL6_64 NETWORK edition. 3. If running any version of Zimbra Collaboration, check if the libssl shared library is built with dlts1_heartbeat: Vulnerable: $ strings /opt/zimbra/openssl/lib/libssl.so | grep dtls1_heartbeat dtls1_heartbeat $ Not Vulnerable: $ strings /opt/zimbra/openssl/lib/libssl.so | grep dtls1_heartbeat $
Please let Zimbra know promptly if any problems or questions.
May 19, 2014 - Thom O'Connor , VP Customer Support
Bug 80338 (Feb 2013) is a Local File Inclusion vulnerability that leads to potential Privilege Escalation
Bug 84547 is a XXE Vulnerability which, among other things, could be abused to disclose information from local files (Dec 2013):
There is great urgency for getting this patched on your platform, as there is an exploit for Bug 80338 in the wild, discussed here:
And it has been used to install upload rogue Zimlets and bitcoin mining processes (and potentially others) on some customer systems. You can read the clean-up steps for this here:
As noted, there are patches and upgrades available here:
Please let us know if further questions. Please upgrade or patch at first opportunity. Sorry for the difficulties on this.
May 19, 2014 - Thom O'Connor , VP Customer Support
Join this group to get the latest news, updates and alerts security issues affecting your Zimbra product.
May 07, 2014 - Jenn Emerson , Community Manager
Zimbra is committed to providing a secure collaboration experience for our customers, partners, and users of our software.
"Watch" the Security Center pages to stay updated on Zimbra security related news.
Open a new Support Ticket or check your opening ones. For questions on becoming a supported Zimbra customer, please us .
Go to our Zimbra Product Releases page for details each release, including:
Try Zimbra Collaboration with a 60-day free trial. Get it now »
Want to get involved?
You can contribute in the Community, Wiki, Code, or development of Zimlets. Find out more. »
User Help Page » Official Forums » Zimbra Documentation Page »
Visit our YouTube channel to get the latest webinars, technology news, product overviews, and so much more. Go to the YouTube channel »
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
