CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
How it works
The weakness is classified as CWE-918, server-side request forgery. In this class of flaw an attacker supplies input that the application uses when making its own outbound requests. The server then performs those requests on the attacker's behalf, which can expose internal services, bypass network boundaries, or retrieve data the attacker could not reach directly.
Am I affected? How to find it in your systems
Zimbra Collaboration Suite runs as an on-premises email and groupware server. Begin by locating every installation through asset inventories, configuration management databases, or network scans for Zimbra services. For each instance determine whether the WebEx zimlet is present and whether zimlet JSP execution is enabled. Exact version numbers and configuration flags must be confirmed against the vendor advisory.
- Examine the zimlet directory and configuration files for WebEx entries.
- Check application logs for unexpected outbound requests originating from the Zimbra server process.
- Review proxy or firewall logs for traffic initiated by the Zimbra host toward internal IP ranges or unexpected external destinations.
How to remediate
Apply the vendor-supplied update or configuration change listed in the official advisory. After patching, review all enabled zimlets and disable any that are not required. Disable zimlet JSP execution if it is not needed for business functions. Follow applicable BOD 22-01 guidance for any cloud-hosted instances.
If you can't patch immediately
Apply mitigations exactly as described in the vendor instructions. Where mitigations cannot be implemented, discontinue use of the affected product. Segment the Zimbra servers so they cannot reach internal resources that should not be accessible from the application tier. Monitor outbound traffic from the servers for anomalies until remediation is complete.
If your data may have been exposed
Vulnerabilities in this class have been leveraged in data breaches. Organizations can run a free exposure scan of their domains to check for presence in known breach data sets.
AICompiled with AI assistance from public sources and published under our editorial standards.