PT-2022-23141 · Unknown · Zulip Server
Andersk
·
Published
2022-08-31
·
Updated
2022-09-08
·
CVE-2022-36048
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip Server versions prior to 5.6
Description
The issue arises when displaying messages with embedded remote images. Normally, Zulip loads the image preview via a go-camo proxy server. However, an attacker who can send messages could include a crafted URL that tricks the server into embedding a remote image reference directly. This could allow the attacker to infer the viewer’s IP address and browser fingerprinting information.
Recommendations
For versions prior to 5.6, update to Zulip Server 5.6 to resolve the issue.
As a temporary workaround, consider disabling image and link previews to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zulip Server