PT-2023-23953 · Unknown · Zulip Server

Alexmv

·

Published

2023-05-19

·

Updated

2024-02-01

·

CVE-2023-32677

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zulip Server versions 6.1 and below
Description Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server, the UI which allows a user to invite a new user also allows them to set the streams that the new user is invited to -- even if the inviting user would not have permissions to add an existing user to streams. While such a configuration is likely rare in practice, the behavior does violate security-related controls. This does not let a user invite new users to streams they cannot see, or would not be able to add users to if they had that general permission.
Recommendations For Zulip Server versions 6.1 and below, users are advised to upgrade to version 6.2 to address the issue. For users unable to upgrade, it is recommended to limit sending of invitations down to users who also have the permission to add users to streams.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-32677
GHSA-MRVP-96Q6-JPVC

Affected Products

Zulip Server