{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "10.0.0"
              },
              {
                "fixed": "10.0.10"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "10.1.0"
              },
              {
                "fixed": "10.1.2"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p30"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p31"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p34"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p35"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p39"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p40"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p41"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "fixed": "9.0.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p19"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p23"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p25"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p26"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p27"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p28"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p33"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p36"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p37"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p38"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "9.0.0-p7\\.1"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "b6cd8f69d2761c014d4a3807f0bdee0011386444"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "de2eedbbdb8d58c34aac58dbf3866ae721f039eb"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "5561a39cba0898c3bb5e188284d98f498d7a3c9a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "c8a93da38fd1572d864c1becbcc772ba91ee4403"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "202d83762fca70b7403c144e1fedddc6cd4930a6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "a163a5dc09ec091fed86421118ec56c90384997a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b2faf1c074bf6e2f4f76acd11b9ad5a0b4caec40"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "0bea2f7ec388cc09cb3de4ee93344df2695b91a8"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "9173353f25559ed524c7a40c799056c01c3418d4"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "c27b145236b09c5487259d943dd54ffdea0ccbb3"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "8d7f3750f42f0a59d61c1b44d8df1000a52ce9f2"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "bc50e7d47c56532b226a1c88c8011127e006940b"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "03d99a16095b73a73770fbb6131d10234cfc13fd"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "bcb978ccc354d99d843725886083e321759b6765"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b20d016c829af1c0ffbaa0545c1deb96ccd5e2e5"
            }
          ],
          "repo": "https://github.com/zimbra/zm-build",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message.\n\nThe specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account. Was ZDI-CAN-23939.",
  "id": "CVE-2024-9665",
  "modified": "2026-03-11T21:47:36.162827006Z",
  "published": "2024-11-22T21:15:23.923Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://blog.zimbra.com/2024/10/new-patch-release-reminders-for-missing-attachments-out-of-office-notifications-traffic-light-protocol-tlp-and-mailto-links/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1369/"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}