Security Flaw in Zulip Bot API Keys Exposing User Data
CVE-2016-4426

4.3MEDIUM

Key Information:

Vendor

Zulip

Status
Vendor
CVE Published:
28 July 2022

What is CVE-2016-4426?

Prior to version 1.3.12 of Zulip, an improper access control vulnerability allowed bot API keys to be accessed by other users within the same realm, potentially compromising sensitive bot actions and user data. This flaw emphasizes the importance of stringent access controls in API key management to prevent unauthorized access and enhance overall security.

Affected Version(s)

zulip zulip 1.3.12

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.