<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									jetty directory listing open - General Info				            </title>
            <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/</link>
            <description>Zextras Community Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 21 Apr 2026 16:57:10 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9945</link>
                        <pubDate>Sun, 09 Feb 2025 17:16:35 +0000</pubDate>
                        <description><![CDATA[I&#039;m running the last version.
 
However, you are very very right about the un-readability of the changelogs and announcements.It&#039;s impossible for admin to know what changed between two ver...]]></description>
                        <content:encoded><![CDATA[
<p></p>
<p>Can't reproduce.</p>
<p>I tried all the ports (and 6071) and I'm getting a 403 each time.</p>
<p></p>
<p>What happens if you try /service/nginx.key or /service/localconfig.xml?</p>
<p></p>
<p>I'm running the last version.</p>
<p> </p>
<p>However, you are very very right about the un-readability of the changelogs and announcements.<br />It's impossible for admin to know what changed between two versions, we do need a functionnal summary (no code reading, clear explanation of what was changed, what is new, what was fixed), especially on security topics.</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Klug</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9945</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9934</link>
                        <pubDate>Wed, 05 Feb 2025 16:19:42 +0000</pubDate>
                        <description><![CDATA[@danijel-tudek 
Hi,
No doubt your feedback has some valid improvement points to consider. We are definitely going to retrospect on this. We appreciate your feedbacks and would love to hear...]]></description>
                        <content:encoded><![CDATA[<p>@danijel-tudek </p>
<p>Hi,</p>
<p>No doubt your feedback has some valid improvement points to consider. We are definitely going to retrospect on this. We appreciate your feedbacks and would love to hear more in future.</p>
<p>Have a good day &#x1f60a;</p>
<p>Regards</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9934</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9933</link>
                        <pubDate>Wed, 05 Feb 2025 16:19:20 +0000</pubDate>
                        <description><![CDATA[@danijel-tudek 
Hi,
No doubt your feedback has some valid improvement points to consider. We are definitely going to retrospect on this. We appreciate your feedbacks and would love to hear...]]></description>
                        <content:encoded><![CDATA[<p>@danijel-tudek </p>
<p>Hi,</p>
<p>No doubt your feedback has some valid improvement points to consider. We are definitely going to retrospect on this. We appreciate your feedbacks and would love to hear more in future.</p>
<p>Have a good day &#x1f60a;</p>
<p>Regards</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9933</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9931</link>
                        <pubDate>Wed, 05 Feb 2025 10:55:19 +0000</pubDate>
                        <description><![CDATA[@sharif 
Thank you for the response. I can confirm that the latest update does fix the issue.
 
I would like to point out that, if there was any announcement, it was not in any easily acc...]]></description>
                        <content:encoded><![CDATA[<p>@sharif </p>
<p>Thank you for the response. I can confirm that the latest update does fix the issue.</p>
<p> </p>
<p>I would like to point out that, if there was any announcement, it was not in any easily accessible and visible place - certainly not on the homepage of community.zextras.com, it's not on the blog, nor in a separate forum thread. I could only find vague information about "security patches" buried on the page 17 of the "New release" thread which does not help with visibility.</p>
<p>Your changelog also doesn't mention it - full changelog from the documentation is actually a number of links to GitHub repositories of applications whose versions don't match Carbonio's versioning. Also, none of those linked changelogs mention changes related to this issue - please correct me if I missed it in some of those changelogs.</p>
<p>One of the most logical places for such announcements would be the update pages in the documentation. A brief changelog summary would also help, because currently there's no way to correlate Carbonio versions (e.g. 24.12.2) to the versions of components (e.g. 0.9.3, 1.14.0, 1.4.1 and so on).</p>
<p>Also, the mail that you mention here, security@zextras.com, is not mentioned anywhere else on your websites, and there's no guidelines for reporting security issues other than the generic suggestion to write here on this forum. Documentation for the paid version talks about "Zextras customer’s support portal", but doesn't mention security issues either. There should be an easily discoverable security advisory web page that would also guide users to confidentially report security issues.</p>
<p>Please consider these suggestions, and thank you.</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>danijel.tudek</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9931</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9927</link>
                        <pubDate>Wed, 05 Feb 2025 08:42:42 +0000</pubDate>
                        <description><![CDATA[Hi @darklight,
Thank you for bringing this to our attention. We would like to provide some clarifications regarding this matter and the steps taken to address the reported vulnerability.
T...]]></description>
                        <content:encoded><![CDATA[<p data-renderer-start-pos="17">Hi @<span>darklight</span>,</p>
<p data-renderer-start-pos="38">Thank you for bringing this to our attention. We would like to provide some clarifications regarding this matter and the steps taken to address the reported vulnerability.</p>
<p data-renderer-start-pos="211">To understand the events in chronological order:</p>
<ul>
<li data-renderer-start-pos="263">The vulnerability was initially identified during internal testing with Carbonio 24.12.0, once identified we verified the vulnerability also affects 24.9</li>
<li data-renderer-start-pos="263">Development work commenced to implement a permanent fix, ensuring that passwords and sensitive data would not be exposed.</li>
<li data-renderer-start-pos="263">The security fix was officially released with Carbonio 24.12.1, along with patched packages for Carbonio 24.9.</li>
<li data-renderer-start-pos="263">The documentation was updated with instructions on the workaround with <a class="cc-1rn59kg" title="https://docs.zextras.com/carbonio/html/troubleshooting/ldap.html" href="https://docs.zextras.com/carbonio/html/troubleshooting/ldap.html" data-testid="link-with-safety" data-renderer-mark="true"><u data-renderer-mark="true">resetting LDAP credentials</u></a> and <a class="cc-1rn59kg" title="https://docs.zextras.com/carbonio-ce/html/troubleshooting/auth.html#ts-auth-keys" href="https://docs.zextras.com/carbonio-ce/html/troubleshooting/auth.html#ts-auth-keys" data-testid="link-with-safety" data-renderer-mark="true"><u data-renderer-mark="true">the PreAuthKey</u></a> when upgrading from Carbonio 24.9 or 24.12.</li>
<li data-renderer-start-pos="263">A public announcement was made regarding the availability of Carbonio 24.12.1, including details on the security fix. </li>
</ul>
<br />
<p data-renderer-start-pos="945">Once we received complete confirmation from our development and security teams, we informed users through multiple channels about the importance of upgrading to version 24.12.1. We were also assisting users using this post about how to <a class="cc-1rn59kg" title="https://community.zextras.com/forum/postid/9759/" href="https://community.zextras.com/forum/postid/9759/" data-testid="link-with-safety" data-renderer-mark="true"><u data-renderer-mark="true">investigate</u></a> and execute the workarounds on LDAP credentials and Pre-Auth Keys.</p>
<p data-renderer-start-pos="1261">Unfortunately, due to the ongoing mitigation efforts, we were unable to address this forum post earlier. However, we sincerely appreciate your diligence in reporting the issue. Given the potential risks associated with this vulnerability, we exercised caution in disclosing details to prevent exploitation by malicious actors. Our priority was to ensure the fix was fully implemented and available before publicly addressing the matter.</p>
<p data-renderer-start-pos="1699">For future security-related concerns, we strongly encourage users to reach out to us directly via <strong><span style="color: #800000">security@zextras.com</span></strong> with relevant technical details<strong>.</strong> This will allow us to assess and resolve vulnerabilities efficiently while safeguarding sensitive information.</p>
<p data-renderer-start-pos="1963"> </p>
<p data-renderer-start-pos="1965"><strong data-renderer-mark="true"><mark id="7687a22c-8d92-4d30-ac39-211abd123933" class="cc-4skef7" data-renderer-mark="true" data-mark-type="annotation" data-mark-annotation-type="inlineComment" data-id="7687a22c-8d92-4d30-ac39-211abd123933" data-mark-annotation-state="resolved" data-has-focus="false" data-is-hovered="false">Relevant suggestion details beside workaround:</mark></strong></p>
<p data-renderer-start-pos="2013">Besides the workaround (With resetting LDAP credentials and the removal of PreAuthKay), we would suggest to update credentials for:</p>
<ul>
<li data-renderer-start-pos="2148">domains using external LDAP authentication (both sides).</li>
<li data-renderer-start-pos="2148">domains using auto-provisioning from external LDAP (both sides)</li>
<li data-renderer-start-pos="2148">videoserver (both sides)</li>
<li data-renderer-start-pos="2148">global server SSL certificate and revoke the old ones.</li>
<li data-renderer-start-pos="2148">domain certificates and revoke the old ones.</li>
<li data-renderer-start-pos="2148">domain DKIM keys (During the DNS update, you can temporarily disable the DKIM signature)</li>
</ul>
<p data-renderer-start-pos="2501"><strong>We recommend all users to upgrade to version 24.12.1 and follow the outlined security steps to ensure the system is fully protected.</strong></p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Sharif</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9927</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9918</link>
                        <pubDate>Mon, 03 Feb 2025 15:03:34 +0000</pubDate>
                        <description><![CDATA[What happens if you try /service/nginx.key or /service/localconfig.xml?]]></description>
                        <content:encoded><![CDATA[
<p>Can't reproduce.</p>
<p>I tried all the ports (and 6071) and I'm getting a 403 each time.</p>
<p></p>
<p>What happens if you try /service/nginx.key or /service/localconfig.xml?</p>
<p> </p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>danijel.tudek</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9918</guid>
                    </item>
				                    <item>
                        <title>RE: jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9917</link>
                        <pubDate>Mon, 03 Feb 2025 13:26:45 +0000</pubDate>
                        <description><![CDATA[Can&#039;t reproduce.
I tried all the ports (and 6071) and I&#039;m getting a 403 each time.
 
HTTP ERROR 403 Forbidden



URI:
/service/


STATUS:
403


MESSAGE:
Forbidden


SERVLE...]]></description>
                        <content:encoded><![CDATA[<p>Can't reproduce.</p>
<p>I tried all the ports (and 6071) and I'm getting a 403 each time.</p>
<p> </p>
<h2>HTTP ERROR 403 Forbidden</h2>
<table>
<tbody>
<tr>
<th>URI:</th>
<td>/service/</td>
</tr>
<tr>
<th>STATUS:</th>
<td>403</td>
</tr>
<tr>
<th>MESSAGE:</th>
<td>Forbidden</td>
</tr>
<tr>
<th>SERVLET:</th>
<td>default</td>
</tr>
</tbody>
</table>
<p> </p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>Klug</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9917</guid>
                    </item>
				                    <item>
                        <title>jetty directory listing open</title>
                        <link>https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9339</link>
                        <pubDate>Mon, 28 Oct 2024 16:09:58 +0000</pubDate>
                        <description><![CDATA[Hello everyone,
i am new to forum. I have just installed zextras community and noticed that server exposes port 7071, 7072, 7073 show directory listing at following path
Directory: /service...]]></description>
                        <content:encoded><![CDATA[<p>Hello everyone,</p>
<p>i am new to forum. I have just installed zextras community and noticed that server exposes port 7071, 7072, 7073 show directory listing at following path https://mail.myreducteddomain.com:7071/service/</p>
<p>Directory: /service/<br />Name ⇧ Last Modified Size<br />amavisd.conf Oct 28, 2024, 4:51:27 PM 40,038 bytes <br />amavisd.conf.in Sep 23, 2024, 7:00:20 PM 41,425 bytes <br />amavisd-custom.conf Sep 23, 2024, 7:00:20 PM 1,003 bytes <br />antisamy.xml Aug 27, 2024, 11:44:14 AM 79,214 bytes <br />attrs/ Oct 28, 2024, 4:36:23 PM 4,096 bytes <br />attrs-schema Oct 18, 2024, 7:43:32 PM 11 bytes <br />ca/ Oct 28, 2024, 4:37:22 PM 4,096 bytes <br />carbonio.ldif Aug 27, 2024, 11:19:46 AM 3,631 bytes <br />cbpolicyd.conf.in Sep 23, 2024, 7:00:20 PM 4,711 bytes <br />clamd.conf Oct 28, 2024, 4:51:27 PM 27,521 bytes <br />clamd.conf.in Sep 23, 2024, 7:00:20 PM 27,718 bytes <br />clamd.conf.sample Jul 25, 2024, 7:09:59 PM 27,505 bytes <br />common-passwords.txt Oct 18, 2024, 7:43:29 PM 8,529,110 bytes <br />contact-fields.xml Oct 18, 2024, 7:43:29 PM 157,101 bytes <br />crontabs/ Sep 28, 2024, 11:21:53 AM 4,096 bytes <br />datasource.xml Oct 18, 2024, 7:43:32 PM 3,926 bytes <br />dhparam.pem Aug 27, 2024, 11:23:48 AM 424 bytes <br />dhparam.pem.crb Aug 27, 2024, 11:20:48 AM 424 bytes <br />domaincerts/ Aug 27, 2024, 11:23:49 AM 4,096 bytes <br />dspam.conf Oct 28, 2024, 4:51:27 PM 28,028 bytes <br />dspam.conf.in Sep 23, 2024, 7:00:20 PM 28,045 bytes <br />externaldirsync/ Oct 28, 2024, 4:36:25 PM 4,096 bytes <br />freshclam.conf Oct 28, 2024, 4:51:27 PM 7,205 bytes <br />freshclam.conf.in Sep 23, 2024, 7:00:20 PM 7,209 bytes <br />freshclam.conf.sample Jul 25, 2024, 7:09:59 PM 7,205 bytes <br />globs2 Oct 18, 2024, 7:43:29 PM 22,418 bytes <br />globs2.zimbra Oct 18, 2024, 7:43:29 PM 335 bytes <br />ldap-canonical.cf Oct 28, 2024, 4:52:10 PM 444 bytes <br />ldap-slm.cf Oct 28, 2024, 4:52:10 PM 604 bytes <br />ldap-splitdomain.cf Oct 28, 2024, 4:52:10 PM 486 bytes <br />ldap-transport.cf Oct 28, 2024, 4:52:10 PM 372 bytes <br />ldap-vad.cf Oct 28, 2024, 4:52:10 PM 360 bytes <br />ldap-vam.cf Oct 28, 2024, 4:52:10 PM 562 bytes <br />ldap-vmd.cf Oct 28, 2024, 4:52:10 PM 360 bytes <br />ldap-vmm.cf Oct 28, 2024, 4:52:10 PM 354 bytes <br />localconfig.xml Sep 29, 2024, 1:59:45 PM 6,267 bytes <br />log4j.properties Oct 28, 2024, 4:51:27 PM 8,845 bytes <br />log4j.properties.in Oct 18, 2024, 7:43:32 PM 9,601 bytes <br />magic Oct 18, 2024, 7:43:29 PM 20,329 bytes <br />magic.zimbra Oct 18, 2024, 7:43:29 PM 63 bytes <br />milter.log4j.properties Oct 18, 2024, 7:43:32 PM 1,320 bytes <br />msgs/ Oct 28, 2024, 4:36:23 PM 16,384 bytes <br />mta_milter_options Oct 28, 2024, 4:51:28 PM 91 bytes <br />mta_milter_options.in Oct 18, 2024, 7:43:32 PM 154 bytes <br />my.cnf Aug 27, 2024, 11:23:16 AM 1,315 bytes <br />nginx/ Aug 27, 2024, 11:24:07 AM 4,096 bytes <br />nginx.conf Oct 28, 2024, 4:51:28 PM 501 bytes <br />nginx.crt Oct 5, 2024, 9:26:36 AM 5,521 bytes <br />nginx.key Oct 5, 2024, 9:26:36 AM 1,704 bytes <br />opendkim.conf Oct 28, 2024, 4:51:27 PM 1,824 bytes <br />opendkim.conf.in Sep 23, 2024, 7:00:20 PM 1,794 bytes <br />opendkim-localnets.conf Oct 28, 2024, 4:51:27 PM 28 bytes <br />opendkim-localnets.conf.in Sep 23, 2024, 7:00:20 PM 31 bytes <br />owasp_policy.xml Aug 27, 2024, 11:44:14 AM 7,815 bytes <br />postfix_header_checks Oct 28, 2024, 4:51:28 PM 452 bytes <br />postfix_header_checks.in Sep 23, 2024, 7:00:20 PM 488 bytes <br />rights/ Oct 28, 2024, 4:36:23 PM 4,096 bytes <br />salocal.cf.in Sep 23, 2024, 7:00:20 PM 4,438 bytes <br />sasl2/ Oct 28, 2024, 4:51:28 PM 4,096 bytes <br />saslauthd.conf Oct 28, 2024, 4:51:27 PM 134 bytes <br />saslauthd.conf.in Sep 23, 2024, 7:00:20 PM 103 bytes <br />slapd.crt Oct 5, 2024, 9:26:35 AM 5,521 bytes <br />slapd.key Oct 5, 2024, 9:26:35 AM 1,704 bytes <br />smtpd.crt Oct 5, 2024, 9:26:36 AM 5,521 bytes <br />smtpd.key Oct 5, 2024, 9:26:36 AM 1,704 bytes <br />spnego_java_options Oct 28, 2024, 4:51:28 PM 3 bytes <br />spnego_java_options.in Oct 18, 2024, 7:43:29 PM 74 bytes <br />stats.conf Oct 28, 2024, 4:51:27 PM 207 bytes <br />stats.conf.in Oct 18, 2024, 7:43:32 PM 45 bytes <br />templates/ May 2, 2024, 5:10:31 PM 4,096 bytes <br />timezones.ics Aug 27, 2024, 6:03:48 PM 161,587 bytes <br />web.xml Oct 28, 2024, 4:51:27 PM 21,999 bytes <br />web.xml.in Oct 18, 2024, 7:43:29 PM 23,094 bytes <br />zmconfigd/ Sep 28, 2024, 11:21:53 AM 4,096 bytes <br />zmconfigd.cf Sep 23, 2024, 7:00:20 PM 21,443 bytes <br />zmconfigd.log4j.properties Sep 23, 2024, 7:00:20 PM 1,791 bytes <br />zmlogrotate Sep 23, 2024, 7:00:20 PM 2,509 bytes <br />zmssl.cnf Aug 27, 2024, 11:18:50 AM 7,899 bytes <br />zmssl.cnf.in Sep 23, 2024, 7:00:20 PM 7,851 bytes</p>
<p>Coul you guru tell how can i disable this dangerous stuff?</p>
<p>thank you all</p>]]></content:encoded>
						                            <category domain="https://community.zextras.com/forum/general-info/">General Info</category>                        <dc:creator>darklight</dc:creator>
                        <guid isPermaLink="true">https://community.zextras.com/forum/general-info/jetty-directory-listing-open/#post-9339</guid>
                    </item>
							        </channel>
        </rss>
		