PT-2020-13176 · Zulip · Zulip Desktop

Published

2020-05-09

·

Updated

2020-05-13

·

CVE-2020-12637

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zulip Desktop versions prior to 5.2.0
Description The issue is related to Missing SSL Certificate Validation. This occurred because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
Recommendations For versions prior to 5.2.0, update to version 5.2.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of the ignoreCerts option until a patch is available. Restrict access to sensitive resources that rely on SSL certificate validation to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12637

Affected Products

Zulip Desktop