Hardcoded Credentials Vulnerability in Zimbra Collaboration by Zimbra
CVE-2025-67809
What is CVE-2025-67809?
A significant security issue exists in Zimbra Collaboration versions 10.0 and 10.1, where a hardcoded Flickr API key and secret are found within the publicly accessible Flickr Zimlet. This vulnerability allows unauthorized individuals to retrieve these embedded credentials, enabling them to impersonate the legitimate application. If a user inadvertently approves an OAuth request initiated with these credentials, an attacker could gain unauthorized access to the user's Flickr data. Fortunately, the hardcoded credentials have been subsequently removed and the associated key has been revoked to enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
