Zimbra Collaboration Memcached CRLF Injection

Strike ID:
E22-eg2c1
CVSS:
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
False Positive:
f
Variants:
1
Year:
2022

Description

This strike exploits a CRLF(Carriage Return followed by Line Feed) Injection vulnerability in the Zimbra Collaboration server. This vulnerability is due to insufficient sanitization of CRLF characters in HTTP Request-URIs and HTTP header values when performing route caching using Memcached. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation could allow an attacker to inject arbitrary Memcached commands which would be executed by the server.

CVE

References