Hi Zextras Community,
We are currently evaluating Carbonio CE as a possible replacement for our existing Zimbra servers, and security is one of the main reasons behind this evaluation.
Recently, several critical vulnerabilities affecting Zimbra have been actively exploited in the wild, including attacks resulting in server compromise and webshell deployment.
Since Carbonio shares or historically originated from some Zimbra components, I would like to better understand the security exposure of Carbonio CE regarding these vulnerabilities.
Specifically:
- Which Zimbra components are still shared or derived from Zimbra in current Carbonio CE releases?
- When a new Zimbra CVE is published, does Zextras evaluate whether the same vulnerable code exists in Carbonio?
- Is there a public security advisory or CVE compatibility/mapping page where administrators can check whether a Zimbra CVE also affects Carbonio CE?
- Are the recent Zimbra vulnerabilities that have been actively exploited against Internet-facing mail servers applicable to Carbonio CE?
- In particular, are vulnerabilities involving Zimbra Web Client / Jetty, SOAP endpoints, file upload/path traversal, SSRF, or remote code execution potentially relevant to Carbonio because of shared components?
- Does Zextras maintain the Zimbra-derived components independently and backport security fixes when necessary?
We currently operate Internet-facing mail infrastructure and have recently investigated malicious activity against Zimbra servers, including attempted exploitation and webshell deployment. Because of this, we want to make sure that migrating to Carbonio CE actually reduces our exposure rather than moving the same vulnerable components to a different platform.
It would be very useful if someone from the Zextras team could clarify the relationship between Zimbra CVEs and Carbonio CE security, particularly for current Carbonio CE releases.
Thank you.
