Zimbra Product Security Update Advisory (CVE-2024-45519)

Overview

 

An update has been released to address vulnerabilities in Zimbra Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

CVE-2024-45519

  • ZCO(Zimbra Connector for Outlook) versions: ~ 10.0.9 (excluded)
  • ZCO(Zimbra Connector for Outlook) versions: ~ 10.1.1 (excluded)
  • ZCO(Zimbra Connector for Outlook) versions: ~ 9.0.0 Patch 41 (excluded)
  • ZCO(Zimbra Connector for Outlook) versions: ~ 8.8.15 Patch 46 (excluded)

 

 

 

Resolved Vulnerabilities

 

Security vulnerability in the postjournal service that allows unauthenticated users to execute commands (CVE-2024-45519)

 

 

Vulnerability Patches

The following product-specific Vulnerability Patches have been made available in the latest update. If you are using an affected version, Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-45519

  • ZCO(Zimbra Connector for Outlook) version: 10.0.9
  • ZCO(Zimbra Connector for Outlook) version: 10.1.1
  • ZCO(Zimbra Connector for Outlook) version: 9.0.0 Patch 41
  • ZCO(Zimbra Connector for Outlook) version: 8.8.15 Patch 46

     

References

 

[1] Zimbra Security – News & Alerts

https://wiki.zimbra.com/wiki/Security_Center