PT-2017-10710 · Zulip · Zulip Server
Vishnu Ks
·
Publicado
2017-11-27
·
Atualizado
2019-10-09
·
CVE-2017-0910
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zulip Server versions prior to 1.7.1
Description
A vulnerability in the invitation system of Zulip Server allows an authorized user of one realm to create a user account on any other realm, given that the server has multiple realms.
Recommendations
For versions prior to 1.7.1, update to version 1.7.1 or later to resolve the issue.
Correção
Incorrect Authorization
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zulip Server