Information Disclosure Vulnerability in Zulip Server by Zulip
CVE-2024-56136

6.9MEDIUM

Key Information:

Vendor

Zulip

Status
Vendor
CVE Published:
16 January 2025

What is CVE-2024-56136?

Zulip Server allows unauthenticated users to determine if an email address is associated with any user on the server when hosting multiple organizations. This occurs due to a vulnerability in Zulip Server versions 7.0 and above. Attackers can exploit this flaw, leading to potential privacy violations for users. The issue has been addressed in Zulip Server 9.4 and in the 'main' branch. It is crucial for users to upgrade to the latest version to mitigate this vulnerability, as there are currently no workarounds available.

Affected Version(s)

zulip >= 7.0, < 9.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-56136 : Information Disclosure Vulnerability in Zulip Server by Zulip