PT-2017-10697 · Zulip · Zulip Server

Ibram Marzouk

·

Publicado

2017-06-02

·

Atualizado

2019-10-03

·

CVE-2017-0896

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zulip Server versions 1.5.1 and below
Description The issue arises from an error in the implementation of the invite by admins only setting in the Zulip group chat application server. This error allows an authenticated user to invite other users to join a Zulip organization, even if the organization is configured to prevent this action.
Recommendations For Zulip Server versions 1.5.1 and below, as a temporary workaround, consider disabling the invite functionality until a patch is available. Restrict access to the organization's settings to minimize the risk of exploitation. Avoid using the invite by admins only setting in configurations where it is intended to restrict invitations.

Correção

Missing Authorization

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-0896

Produtos afetados

Zulip Server