PT-2025-16904 · Zulip · Zulip
Timabbott
·
Published
2025-04-16
·
Updated
2026-01-23
·
CVE-2025-31478
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip versions prior to 10.2
Description
A bug in the Zulip server allows account creation without authenticating with the configured Single Sign-On (SSO) authentication backend in organizations where account creation is limited solely by SSO authentication and email/password authentication is disabled. This issue can be exploited to create an account without having an account with the configured SSO authentication backend.
Recommendations
For versions prior to 10.2, update to version 10.2 to resolve the issue.
As a temporary workaround, consider requiring invitations to join the organization to prevent the vulnerability from being accessed.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zulip