Access Control Flaw in Zulip Server by Zulip
CVE-2020-14215
7.5HIGH
What is CVE-2020-14215?
A vulnerability exists in Zulip Server before version 2.1.5, where an improper access control mechanism allows the administrator role to be assigned to user invitations unintentionally. This misconfiguration can lead to unauthorized users gaining elevated privileges, compromising the security of the server and its communications. Users are advised to update to version 2.1.5 or later to mitigate this risk.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
