PT-2019-14585 · Zulip · Zulip Server
CVE-2019-16215
·
Publicado
2019-09-18
·
Atualizado
2024-02-08
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Zulip server versions prior to 2.0.5
Description
The issue concerns the Markdown parser in the Zulip server, which used a regular expression vulnerable to exponential backtracking. This could allow a logged-in user to send a crafted message, causing the server to spend an arbitrary amount of CPU time and stall the processing of future messages.
Recommendations
For versions prior to 2.0.5, update to version 2.0.5 or later to resolve the issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zulip Server