Autsubscribe Flaw in Zulip Group Chat Application
CVE-2017-0881
4.3MEDIUM
What is CVE-2017-0881?
A flaw in the autosubscribe feature of the Zulip group chat application's check_stream_exists route permitted authenticated users to subscribe to private streams without the necessary invitation. This vulnerability affects all versions of the Zulip server prior to 1.4.3, potentially compromising user privacy and the integrity of private conversations.
Affected Version(s)
Zulip Server 1.4.2 and below Zulip Server Versions 1.4.2 and below
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
