PT-2022-20461 · Zulip+1 · Zulip+1
Alexmv
·
Published
2022-06-25
·
Updated
2022-07-07
·
CVE-2022-31017
CVSS v2.0
2.1
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip versions 2.1.0 through 5.2
Description
The issue is related to a logic error in Zulip, an open-source team collaboration tool. When a stream configured as private with protected history is edited, the server incorrectly sends an API event that includes the edited message to all of the stream’s current subscribers. This API event is ignored by official clients but can be observed using a modified client or the browser’s developer tools.
Recommendations
For versions 2.1.0 through 5.2, update to Zulip Server 5.3 to resolve the issue.
As a temporary workaround, consider restricting access to edited streams to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zulip
Zulip Server