Host Header Vulnerability in Zimbra Collaboration Suite by Zimbra
CVE-2022-37041
What is CVE-2022-37041?
A security vulnerability exists in the ProxyServlet component of Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0. The flaw occurs due to the unvalidated use of the X-Forwarded-Host header, which is improperly allowed to overwrite the Host header in proxied requests. This oversight means that the value being forwarded is not subjected to an appropriate whitelist check against the zimbraProxyAllowedDomains setting, potentially allowing unauthorized redirection or manipulation of requests that could impact the integrity and security of messaging services within ZCS.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
