PT-2019-14585 · Zulip · Zulip Server

CVE-2019-16215

·

Publicado

2019-09-18

·

Atualizado

2024-02-08

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zulip server versions prior to 2.0.5
Description The issue concerns the Markdown parser in the Zulip server, which used a regular expression vulnerable to exponential backtracking. This could allow a logged-in user to send a crafted message, causing the server to spend an arbitrary amount of CPU time and stall the processing of future messages.
Recommendations For versions prior to 2.0.5, update to version 2.0.5 or later to resolve the issue.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16215

Produtos afetados

Zulip Server