PT-2017-10710 · Zulip · Zulip Server
Vishnu Ks
·
Published
2017-11-27
·
Updated
2019-10-09
·
CVE-2017-0910
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zulip Server versions prior to 1.7.1
Description
A vulnerability in the invitation system of Zulip Server allows an authorized user of one realm to create a user account on any other realm, given that the server has multiple realms.
Recommendations
For versions prior to 1.7.1, update to version 1.7.1 or later to resolve the issue.
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zulip Server