Patch Security Severity: Medium Deployment Risk: Low This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.1.2 (Release Notes) Zimbra Daffodil 10.0.10 (Release Notes) Zimbra 9.0.0 Patch-42 (Release Notes) Support, security patches, or updates for Zimbra 9.0.0 General Support will last through 12/31/2024 Patch updated on Oct 08 […]
Archive | Security & Privacy
Zimbra CVE-2024-45519 Vulnerability – Stay Secure by Updating
Recently, a critical vulnerability affecting Zimbra’s postjournal service (CVE-2024-45519) was identified and is now disclosed on various security websites. The good news? Postjournal service is not enabled by default and Zimbra has already patched this vulnerability. This patch was published in early September. Read the blog post here. Patch Release: Multiple security issues related to […]
Enhance Zimbra Security with AuditD and ACLs
Auditd (Linux Audit Daemon) can be used to capture detailed information about file accesses, system calls, and user actions. Auditd provides administrators the ability to track changes and identify suspicious activities and potentially get an early warning on system compromise by hackers. Adding Auditd to your system will give you more detailed logs, but it […]
Patch Release: Multiple security issues related to Cross-Site Scripting (XSS) addressed and resolved
Patch Security Severity: Medium Deployment Risk: Medium This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.1.1 (Release Notes) Zimbra Daffodil 10.0.9 (Release Notes) Zimbra 9.0.0 Patch-41 (Release Notes) Support, security patches, or updates for Zimbra 9.0.0 General Support will last through 12/31/2024 One-time fix for Zimbra 8.8.15 […]
Prevent Host header injection vulnerability in Zimbra
This is an old issue but Zimbra installations can have a very long life span, in addition it is a good precaution to validate your configuration, just in case. Zimbra Proxy has the ability to strictly enforce which values are allowed in the Host header passed in by the client. This is enabled by default […]
Enhance password security by rejecting common and leaked passwords
In this article you will learn: How to prevent users from choosing common passwords How to add leaked passwords to the list of passwords to reject Enabled the Reject Common Passwords feature You can enable the Zimbra Reject Common Passwords on a per account basis or for an entire Class Of Service (CoS). To enable […]