PT-2022-20461 · Zulip+1 · Zulip+1

Alexmv

·

Published

2022-06-25

·

Updated

2022-07-07

·

CVE-2022-31017

CVSS v2.0

2.1

Low

VectorAV:N/AC:H/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zulip versions 2.1.0 through 5.2
Description The issue is related to a logic error in Zulip, an open-source team collaboration tool. When a stream configured as private with protected history is edited, the server incorrectly sends an API event that includes the edited message to all of the stream’s current subscribers. This API event is ignored by official clients but can be observed using a modified client or the browser’s developer tools.
Recommendations For versions 2.1.0 through 5.2, update to Zulip Server 5.3 to resolve the issue. As a temporary workaround, consider restricting access to edited streams to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31017
GHSA-M5J3-JP59-6F3Q

Affected Products

Zulip
Zulip Server