X-Forwarded-Host Overrides Host in ZCS 8.8.15/9.0 ProxyServlet - Host Hijack
CVE-2022-37041 Published on August 12, 2022

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).

NVD


Products Associated with CVE-2022-37041

stack.watch emails you whenever new vulnerabilities are published in Zimbra Collaboration or Zimbra Collaboration Suite. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.30%
Percentile
53.28%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.