First published: Mon Nov 27 2017(Updated: )
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0910 is considered a medium to high severity vulnerability due to its potential to compromise user accounts across different realms.
To fix CVE-2017-0910, update your Zulip Server to version 1.7.1 or later.
CVE-2017-0910 allows an authorized user from one realm to create accounts on other realms, posing risks to user privacy and security.
Any Zulip Server installation prior to version 1.7.1, specifically those with multiple realms, is affected by CVE-2017-0910.
A temporary workaround for CVE-2017-0910 is to restrict unauthorized users from accessing the invitation system until an update is applied.