在 Zimbra Collaboration (ZCS) 10.1.17 版本之前,OnlyOffice 集成中存在一个弱加密密钥生成漏洞。其中, 是使用一个不安全的随机数生成器生成的,导致熵值不足。攻击者若获取到使用该密钥签名的 JWT(JSON Web Token),可能能够通过离线暴力破解的方式恢复出 JWT 签名密钥,从而可能实现 JWT 伪造。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Collaboration | < 10.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Collaboration | 0 ~ 10.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73570 | 8.9 HIGH | Zimbra<10.1.20 SNMP未授权远程代码执行漏洞 |
| CVE-2026-73572 | 6.1 MEDIUM | Zimbra <10.1.17 存储型XSS漏洞 |
| CVE-2026-73575 | 3.1 LOW | ZCS<10.1.17 CSRF漏洞 |
| CVE-2026-73573 | 3.1 LOW | Zimbra Collaboration <10.1.17 路径穿越漏洞 |
| CVE-2026-73571 | 3.1 LOW | Zimbra Collaboration <10.1.17 授权绕过漏洞 |
| CVE-2026-73574 | 3.1 LOW | Zimbra<10.1.17经典Web客户端LFI漏洞 |
No comments yet