First published: Thu Jul 28 2022(Updated: )
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Desktop | <1.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4426 is a vulnerability in Zulip before version 1.3.12 where bot API keys were accessible to other users in the same realm.
CVE-2016-4426 has a severity rating of medium with a CVSS score of 4.3.
CVE-2016-4426 affects Zulip versions prior to 1.3.12, where bot API keys were accessible to other users in the same realm.
To fix CVE-2016-4426, upgrade to Zulip version 1.3.12 or later.
More information about CVE-2016-4426 can be found at the Zulip documentation: https://zulip.readthedocs.io/en/2.1.7/overview/changelog.html#id35.