X-Forwarded-Host Overrides Host in ZCS 8.8.15/9.0 ProxyServlet - Host Hijack
CVE-2022-37041 Published on August 12, 2022

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).

NVD


Products Associated with CVE-2022-37041

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-37041 are published in these products:

 
 

Exploit Probability

EPSS
0.30%
Percentile
53.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.