PT-2025-16904 · Zulip · Zulip

Timabbott

·

Publicado

2025-04-16

·

Atualizado

2026-01-23

·

CVE-2025-31478

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zulip versions prior to 10.2
Description A bug in the Zulip server allows account creation without authenticating with the configured Single Sign-On (SSO) authentication backend in organizations where account creation is limited solely by SSO authentication and email/password authentication is disabled. This issue can be exploited to create an account without having an account with the configured SSO authentication backend.
Recommendations For versions prior to 10.2, update to version 10.2 to resolve the issue. As a temporary workaround, consider requiring invitations to join the organization to prevent the vulnerability from being accessed.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-31478
GHSA-QXFV-J6VG-5RQC

Produtos afetados

Zulip