Medium severity6.5NVD Advisory· Published Mar 20, 2020· Updated Jun 17, 2026
CVE-2020-10194
CVE-2020-10194
Description
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- Zimbra/zm-mailboxdescription
cpe:2.3:a:zimbra:zm-mailbox:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:zimbra:zm-mailbox:*:*:*:*:*:*:*:*range: <8.8.15
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:-:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch1:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch2:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch3:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch4:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch5:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch6:*:*:*:*:*:*
- cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch7:*:*:*:*:*:*
- (no CPE)range: <8.8.15.p8
Patches
Vulnerability mechanics
References
3- github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1envdPatchThird Party Advisory
- github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8nvdPatchThird Party Advisory
- github.com/Zimbra/zm-mailbox/pull/1020nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.