PT-2019-14585 · Zulip · Zulip Server

Published

2019-09-18

·

Updated

2024-02-08

·

CVE-2019-16215

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zulip server versions prior to 2.0.5
Description The issue concerns the Markdown parser in the Zulip server, which used a regular expression vulnerable to exponential backtracking. This could allow a logged-in user to send a crafted message, causing the server to spend an arbitrary amount of CPU time and stall the processing of future messages.
Recommendations For versions prior to 2.0.5, update to version 2.0.5 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2019-16215

Affected Products

Zulip Server