CVE Vulnerabilities

CVE-2022-3569

Published: Oct 17, 2022 | Modified: Jul 21, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the zimbra user can effectively coerce postfix into running arbitrary commands as root.

Affected Software

Name Vendor Start Version End Version
Zimbra_collaboration_suite Synacor * 9.0.0 (including)

References