CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://wiki.zimbra.com/wiki/ZimbraResponsibleDisclosurePolicy, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?fieldcve=CVE-2024-45519, https://wiki.zimbra.com/wiki/SecurityCenter, https://wiki.zimbra.com/wiki/ZimbraReleases/10.0.9#SecurityFixes, https://wiki.zimbra.com/wiki/ZimbraReleases/10.1.1#SecurityFixes, https://wiki.zimbra.com/wiki/ZimbraReleases/8.8.15/P46#SecurityFixes, https://wiki.zimbra.com/wiki/ZimbraReleases/9.0.0/P41#Security_Fixes, https://blog.projectdiscovery.io/zimbra-remote-code-execution/
