Home

Description

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

PUBLISHED Reserved 2025-02-03 | Published 2025-02-03 | Updated 2025-03-13 | Assigner mitre

References

wiki.zimbra.com/wiki/Zimbra_Security_Advisories

wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4

wiki.zimbra.com/wiki/Zimbra_Releases/10.0.12

wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P43

cve.org (CVE-2025-25065)

nvd.nist.gov (CVE-2025-25065)

Download JSON