CVE-2022-41352
Executive Summary
Zimbra Collaboration 8.8.15/9.0 is vulnerable to an amavis cpio extraction flaw that allows attackers to upload arbitrary files to /opt/zimbra/jetty/webapps/zimbra/public, enabling unauthorized access to other user accounts. The issue is actively exploited (CISA KEV). Installing pax (preferred over cpio) mitigates the risk, but pax is absent from default RHEL installations post‑RHEL6.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2022-09-26T02:15:10.733 - Last Modified: 2026-09-10T04:17:37.410
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-10-20)
Original Description: An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.
"He who talks more is sooner exhausted."
— Lao Tzu