PT-2024-21794 · Zulip · Zulip
Alexmv
·
Published
2024-03-20
·
Updated
2025-09-03
·
CVE-2024-27286
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip versions 3.0 through 8.2
Description
The issue arises when a user moves a Zulip message from a public stream to a private stream, and chooses to move just that single message. In such cases, active users without access to the private stream, but whose client had already received the message, would continue to see the message in the public stream until they reloaded their client. Furthermore, Zulip did not remove view permissions on the message from recently-active users, allowing the message to show up in the "All messages" view or in search results. This bug has been present since version 3.0, but became more common starting in Zulip 8.0.
Recommendations
For Zulip versions 3.0 through 8.2, upgrade to Zulip Server 8.3 to resolve the issue.
As a temporary workaround, consider reloading the client to ensure the message is no longer visible in the public stream.
Restrict access to moved messages to minimize the risk of information disclosure until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zulip