Message Forging Vulnerability in Zulip Server by Zulip
CVE-2021-30478

4.3MEDIUM

Key Information:

Vendor

Zulip

Vendor
CVE Published:
15 April 2021

What is CVE-2021-30478?

A vulnerability has been identified in Zulip Server affecting versions prior to 3.4, where a flaw in the handling of the can_forge_sender permission allows users with this privilege to send messages that appear to originate from a system bot. This issue can extend to users across organizations hosted on the same Zulip installation, potentially leading to confusion and misinformation due to the unauthorized representation of messages. It is crucial for administrators to address this vulnerability to safeguard the integrity of communication within their platforms.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.