Information Leakage Vulnerability in Zulip Team Chat Application
CVE-2025-25195

4.3MEDIUM

Key Information:

Vendor
Zulip
Status
Zulip
Vendor
CVE Published:
13 February 2025

Summary

An information leakage issue existed in the Zulip team chat application where notifications related to private channels were improperly sent to all users within an organization. When a private channel became inactive due to lack of traffic over 180 days, an event revealing the private channel's name was broadcasted to all users. This vulnerability compromised channel confidentiality and posed a risk of inadvertent exposure of private conversation topics. The issue was rectified in subsequent commits, preventing unauthorized visibility of channel names within the user base.

Affected Version(s)

zulip >= 50256f48314250978f521ef439cafa704e056539, < 75be449d456d29fef27e9d1828bafa30174284b4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.