Eval Injection Vulnerability in Zulip Server by Zulip
CVE-2020-15070

8.8HIGH

Key Information:

Vendor

Zulip

Vendor
CVE Published:
21 August 2020

What is CVE-2020-15070?

Zulip Server prior to version 2.1.7 contains a vulnerability that allows a privileged attacker to perform eval injection by writing malicious custom profile field values directly into the Postgres database. This can lead to unauthorized execution of arbitrary code, potentially compromising the integrity of the system. It is crucial for users running affected versions to update to the latest release to mitigate this risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.