Zimbra not affected by log4j (CVE-2021-44228)
After intensive review and testing, Zimbra Development determined that the 0-day exploit vulnerability for log4j (CVE-2021-44228) does not affect the current Supported Zimbra versions (9.0.0 & 8.8.15). Zimbra Collaboration Server currently uses log4j1 version 1.2.16 which doesn't contain the lookup expression feature that is found within versions 2.0 to 2.17, which is the cause of the vulnerability. Also, Redhat (CVE-2021-4104) vulnerability does not affect the Zimbra Collaboration Server version (8.8.15 & 9.0.0). For this vulnerability to affect the server, it needs JMSAppender, which the ZCS Server does not use, and the ability to append configuration files.
After intensive review and testing, Zimbra Development determined that the 0-day exploit vulnerability for log4j (CVE-2021-44228) does not affect the current Supported Zimbra versions (9.0.0 & 8.8.15). Zimbra Collaboration Server currently uses log4j1 version 1.2.16 which doesn't contain the lookup expression feature that is found within versions 2.0 to 2.17, which is the cause of the vulnerability. Also, Redhat (CVE-2021-4104) vulnerability does not affect the Zimbra Collaboration Server version (8.8.15 & 9.0.0). For this vulnerability to affect the server, it needs JMSAppender, which the ZCS Server does not use, and the ability to append configuration files.
Search found 197 matches: administrators/16950-solved-imap_open-access-mailbox-php.html
Searched query: administrators 16950-solved-imap open-access-mailbox-php html
ignored: php html imap solved access open mailbox
- Thu Dec 30, 2021 6:45 pm
- Forum: Administrators
- Topic: Error renewing SSL
- Replies: 1
- Views: 398
Error renewing SSL
I noticed that several administrators are experiencing this problem. I'm trying to update my server's certificates but it returns the following message: -ERROR: Unable to validate certificate chain: C = US, O = Internet Security Research Group, CN = ISRG Root X1 error 2 at 2 depth lookup: unable to ...
- Sat Dec 11, 2021 7:26 pm
- Forum: Administrators
- Topic: log4j-zero-day exploit - active attacks
- Replies: 43
- Views: 14649
Re: log4j-zero-day exploit - active attacks
I came to the conclusion yesterday (probably spent too many hours just with Zimbra) that we were probably fine but continued to work on this that are not zimbra specific in case we were not. I also spent a lot of time looking at various payloads from some of the RCE's. A few vendors still haven't fi...
- Tue Nov 09, 2021 4:12 pm
- Forum: Community News
- Topic: New collaboration system from creator of Zimbra Suite Plus
- Replies: 2
- Views: 3714
New collaboration system from creator of Zimbra Suite Plus
Zextras announces Carbonio, open-source email and collaboration for the growing segment of data sovereignty conscious organizations Paris and Milan, November 9, 2021 – Zextras announces Carbonio, the first open-source solution for email and collaboration targeted to the growing segment of organizati...
- Mon Nov 08, 2021 10:10 pm
- Forum: Administrators
- Topic: Remote Server returned '550 5.7.129 RESOLVER.RST.RestrictedToRecipientsPermission
- Replies: 0
- Views: 1513
Remote Server returned '550 5.7.129 RESOLVER.RST.RestrictedToRecipientsPermission
Client appears to be using O365. We are using Zimbra. Client has reported this error when sending an email to one of our employees: Diagnostic information for administrators: Generating server: ********.com *****@*******.com Remote Server returned '550 5.7.129 RESOLVER.RST.RestrictedToRecipientsPerm...
- Thu Nov 04, 2021 3:12 pm
- Forum: Administrators
- Topic: pyzimbra_delete: Mass delete messages according to conditions
- Replies: 0
- Views: 959
pyzimbra_delete: Mass delete messages according to conditions
Hi fellow administrators, sometime ago I did a wrapper around zmmailbox in python because I did not like to use bash directly, I never get to publish it, I am doing it now. For example: To delete all messages before November 2019 from all accounts in the server with attachment larger than 5MB and lo...
- Wed Jul 07, 2021 2:30 am
- Forum: Administrators
- Topic: Open Source, an interesting read
- Replies: 7
- Views: 18804
Re: Open Source, an interesting read
Hi There, Perhaps I can help. I'll try to answer your feedback as best as possible, but let me say that Open Source is something we want and need to be better at. there is a problem whit many years of open source zimbra, and now only closed pay to use version. Almost all of the Zimbra server source ...
- Fri Jun 18, 2021 5:24 am
- Forum: Community News
- Topic: June 2021 Zeta Alliance Weekly Call Summaries
- Replies: 2
- Views: 8421
Re: June 2021 Zeta Alliance Weekly Call Summaries
... where the Zimbra development team is located, Ubuntu 20.04 support has been pushed back to later this Summer. Simultaneously Updating Zimbra Mailbox Servers Matthew F. asked if anyone on the call patches multiple Zimbra mailbox servers simultaneously, or if they patch mailbox servers sequentially, ...
- Thu Apr 22, 2021 6:51 pm
- Forum: Community News
- Topic: April 2021 Zeta Alliance Weekly Call Summaries
- Replies: 4
- Views: 6619
Re: April 2021 Zeta Alliance Weekly Call Summaries
... but did not see any deep scans occurring. Mark S. said that it may not be a deep scan necessarily, but appeared to be going through every mailbox (15 million objects), and was running for 3+ hours, when it normally takes about 5 minutes to complete a SmartScan process. Cost Savings When ...
- Wed Apr 21, 2021 5:00 am
- Forum: Community News
- Topic: April 2021 Zeta Alliance Weekly Call Summaries
- Replies: 4
- Views: 6619
April 2021 Zeta Alliance Weekly Call Summaries
... support is now supported end-to-end from the Zimbra Nginx proxy to the mailbox server. John H. said that HTTP/2 support is currently only supported ... The fourth vulnerability requires an attacker to have local shell access to a Zimbra server where ClamAV is installed to exploit, making the ...
- Wed Apr 14, 2021 5:15 pm
- Forum: Community News
- Topic: February 2021 Zeta Alliance Weekly Call Summaries
- Replies: 2
- Views: 5652
Re: February 2021 Zeta Alliance Weekly Call Summaries
Hello Zimbra Community, Here is a summary of this week’s conference call. A few brief reminders: ⋅ Conference calls are every Tuesday and open to all using either the FreeConferenceCall.com VoIP app or via a dial-in number: https://www.freeconferencecall.com/wall/zetalliance ⋅ Ea...
