PT-2022-23141 · Unknown · Zulip Server

Andersk

·

Published

2022-08-31

·

Updated

2022-09-08

·

CVE-2022-36048

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zulip Server versions prior to 5.6
Description The issue arises when displaying messages with embedded remote images. Normally, Zulip loads the image preview via a go-camo proxy server. However, an attacker who can send messages could include a crafted URL that tricks the server into embedding a remote image reference directly. This could allow the attacker to infer the viewer’s IP address and browser fingerprinting information.
Recommendations For versions prior to 5.6, update to Zulip Server 5.6 to resolve the issue. As a temporary workaround, consider disabling image and link previews to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-36048
GHSA-VG5M-MF9X-J452

Affected Products

Zulip Server