PT-2024-18982 · Zulip · Zulip

Alexmv

·

Published

2024-01-25

·

Updated

2024-02-01

·

CVE-2024-21630

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zulip version 8.0
Description A vulnerability in Zulip affects installations where non-admins can invite users and create multi-use invitations, but only admins can invite users to streams. This issue allows users to invite new users to streams they can already see, but not to arbitrary streams. The estimated number of potentially affected devices is not specified.
Recommendations For version 8.0, as a temporary workaround, administrators can limit the sending of invitations to users who also have the permission to add users to streams. For version 8.0, update to version 8.1 to resolve the issue.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-21630
GHSA-87P9-WPRH-7RM6
GHSA-MRVP-96Q6-JPVC

Affected Products

Zulip