First published: Tue Mar 28 2017(Updated: )
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0881 is considered a medium severity vulnerability due to its impact on the privacy of private streams.
To fix CVE-2017-0881, upgrade to Zulip Server version 1.4.3 or later.
CVE-2017-0881 affects authenticated users of Zulip group chat applications prior to version 1.4.3.
The primary vulnerability in CVE-2017-0881 is an error in the autosubscribe feature that allows unauthorized access to private streams.
Yes, CVE-2017-0881 allows authenticated users to subscribe to private streams without the required invitation.