Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Have a great idea for extending Zimbra? Share ideas, ask questions, contribute, and get feedback.
Post Reply
User avatar
adrian.gibanel.btactic
Outstanding Member
Outstanding Member
Posts: 568
Joined: Thu Jan 30, 2014 11:13 am
Contact:

Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by adrian.gibanel.btactic »

I have updated Zimbra Foss CVE Commits page to include 10.1.13 CVE commits.

I ask for community help so that the 10.0.18 commits (which should be similar to the 10.1.13 ones) are filled. Otherwise they will left blank.

Thank you.
zmcontrol
Advanced member
Advanced member
Posts: 70
Joined: Fri Jul 24, 2020 12:43 am

Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by zmcontrol »

adrian.gibanel.btactic,

Much thanks for creating and updating this ever more important CVE page.
Unfortunately I have nothing to add to 10.0.18, but the final commit for 10.1.13 that's missing can be found here:

https://github.com/Zimbra/zm-mailbox/co ... d1bbf52d96

Added input validation and null checks in the PreAuthServlet to prevent internal error disclosure on malformed requests
ghen
Outstanding Member
Outstanding Member
Posts: 413
Joined: Thu May 12, 2016 1:56 pm
Location: Belgium

Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by ghen »

Zimbra 10.0 is EOL now, so maybe focus the effort on 10.1 only, or the latest release in general.
User avatar
adrian.gibanel.btactic
Outstanding Member
Outstanding Member
Posts: 568
Joined: Thu Jan 30, 2014 11:13 am
Contact:

Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by adrian.gibanel.btactic »

zmcontrol wrote: Thu Jan 08, 2026 3:14 pm adrian.gibanel.btactic,

Much thanks for creating and updating this ever more important CVE page.
But the final commit for 10.1.13 that's missing can be found here:

https://github.com/Zimbra/zm-mailbox/co ... d1bbf52d96

Added input validation and null checks in the PreAuthServlet to prevent internal error disclosure on malformed requests
Thank you for the catch! I updated the CVE page accordingly.
User avatar
adrian.gibanel.btactic
Outstanding Member
Outstanding Member
Posts: 568
Joined: Thu Jan 30, 2014 11:13 am
Contact:

Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by adrian.gibanel.btactic »

ghen wrote: Thu Jan 08, 2026 3:27 pm Zimbra 10.0 is EOL now, so maybe focus the effort on 10.1 only, or the latest release in general.
10.0.18 was supported recently.

After 10.0.18, yes, all the efforts will be centered on 10.1.x or newer versions.
User avatar
adrian.gibanel.btactic
Outstanding Member
Outstanding Member
Posts: 568
Joined: Thu Jan 30, 2014 11:13 am
Contact:

Re: Zimbra Foss CVE Commits - 10.0.18 update (Ask for help)

Post by adrian.gibanel.btactic »

adrian.gibanel.btactic wrote: Thu Jan 08, 2026 1:48 pm I ask for community help so that the 10.0.18 commits (which should be similar to the 10.1.13 ones) are filled. Otherwise they will left blank.
I have finally updated those CVE commits for 10.0.18.

Unfortunately the CVE-2025-68645 commits for 10.0.18 are missing.
Post Reply