Hardcoded Credentials Vulnerability in Zimbra Collaboration by Zimbra
CVE-2025-67809

4.7MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
15 December 2025

What is CVE-2025-67809?

A significant security issue exists in Zimbra Collaboration versions 10.0 and 10.1, where a hardcoded Flickr API key and secret are found within the publicly accessible Flickr Zimlet. This vulnerability allows unauthorized individuals to retrieve these embedded credentials, enabling them to impersonate the legitimate application. If a user inadvertently approves an OAuth request initiated with these credentials, an attacker could gain unauthorized access to the user's Flickr data. Fortunately, the hardcoded credentials have been subsequently removed and the associated key has been revoked to enhance security.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.