First published: Thu Jul 28 2022(Updated: )
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Desktop | <1.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2016-4427.
The title of the vulnerability is 'In zulip before 1.3.12 deactivated users could access messages if SSO was enabled.'
The severity of CVE-2016-4427 is high, with a severity value of 7.5.
Zulip versions up to but excluding 1.3.12 are affected by CVE-2016-4427.
To fix the vulnerability described in CVE-2016-4427, upgrade to Zulip version 1.3.12 or higher.