PT-2017-10697 · Zulip · Zulip Server

Ibram Marzouk

·

Published

2017-06-02

·

Updated

2019-10-03

·

CVE-2017-0896

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zulip Server versions 1.5.1 and below
Description The issue arises from an error in the implementation of the invite by admins only setting in the Zulip group chat application server. This error allows an authenticated user to invite other users to join a Zulip organization, even if the organization is configured to prevent this action.
Recommendations For Zulip Server versions 1.5.1 and below, as a temporary workaround, consider disabling the invite functionality until a patch is available. Restrict access to the organization's settings to minimize the risk of exploitation. Avoid using the invite by admins only setting in configurations where it is intended to restrict invitations.

Fix

Missing Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0896

Affected Products

Zulip Server