synaccor has published a new patch for Zimbra9 (kind of emergency)
It looks like web interface vulnerabilities...the release notes are at the link above...
We are a long time Zextras partner and I thank Zextras for Zimbra 9 OSE!
G
Hi,
any news regarding the CVE? It's a silly situation as Synacor even patchported the patch to 8.8.15 it means that the systems that didn't go to Zextras v9 but stayed on the unsupported version are now updated, but a properly (I suppose, right?) maintained server now doesn't seem to yet have the patch.
This certainly looks like more than an average Cross-Site-Scripting thing... Maluda's Builds are also not available for P41 yet. Time to enter panic-mode...
there have been no move to fix the situation, but while there is a new issue :
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P42