PT-2023-23953 · Unknown · Zulip Server
Alexmv
·
Published
2023-05-19
·
Updated
2024-02-01
·
CVE-2023-32677
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip Server versions 6.1 and below
Description
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server, the UI which allows a user to invite a new user also allows them to set the streams that the new user is invited to -- even if the inviting user would not have permissions to add an existing user to streams. While such a configuration is likely rare in practice, the behavior does violate security-related controls. This does not let a user invite new users to streams they cannot see, or would not be able to add users to if they had that general permission.
Recommendations
For Zulip Server versions 6.1 and below, users are advised to upgrade to version 6.2 to address the issue.
For users unable to upgrade, it is recommended to limit sending of invitations down to users who also have the permission to add users to streams.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zulip Server