Patch Security Severity: Medium Deployment Risk: Low This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.1.3 (Release Notes) Zimbra Daffodil 10.0.11 (Release Notes) Existing Zimbra 9 customers have until 06/30/2025 to upgrade to the new version (Daffodil v10). Patch updated on Nov 12th includes the following for […]
Archive | Security & Privacy
Patch Release: Reminders for missing attachments, out-of-office notifications, Traffic Light Protocol (TLP), and mailto links.
Patch Security Severity: Medium Deployment Risk: Low This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.1.2 (Release Notes) Zimbra Daffodil 10.0.10 (Release Notes) Zimbra 9.0.0 Patch-42 (Release Notes) Support, security patches, or updates for Zimbra 9.0.0 General Support will last through 12/31/2024 Patch updated on Oct 08 […]
Zimbra CVE-2024-45519 Vulnerability – Stay Secure by Updating
Recently, a critical vulnerability affecting Zimbra’s postjournal service (CVE-2024-45519) was identified and is now disclosed on various security websites. The good news? Postjournal service is not enabled by default and Zimbra has already patched this vulnerability. This patch was published in early September. Read the blog post here. Patch Release: Multiple security issues related to […]
Enhance Zimbra Security with AuditD and ACLs
Auditd (Linux Audit Daemon) can be used to capture detailed information about file accesses, system calls, and user actions. Auditd provides administrators the ability to track changes and identify suspicious activities and potentially get an early warning on system compromise by hackers. Adding Auditd to your system will give you more detailed logs, but it […]
Patch Release: Multiple security issues related to Cross-Site Scripting (XSS) addressed and resolved
Patch Security Severity: Medium Deployment Risk: Medium This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.1.1 (Release Notes) Zimbra Daffodil 10.0.9 (Release Notes) Zimbra 9.0.0 Patch-41 (Release Notes) Support, security patches, or updates for Zimbra 9.0.0 General Support will last through 12/31/2024 One-time fix for Zimbra 8.8.15 […]
Prevent Host header injection vulnerability in Zimbra
This is an old issue but Zimbra installations can have a very long life span, in addition it is a good precaution to validate your configuration, just in case. Zimbra Proxy has the ability to strictly enforce which values are allowed in the Host header passed in by the client. This is enabled by default […]