VulnerabilityAnalyzed
CVE-2025-25065
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
MEDIUM 5.3EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
References
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.12#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P43#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.