First published: Fri Aug 21 2020(Updated: )
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <2.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14215 is a vulnerability in Zulip Server before version 2.1.5 that allows incorrect access control.
CVE-2020-14215 affects Zulip Server versions before 2.1.5 and adds the administrator role to invitations.
CVE-2020-14215 has a severity rating of high.
To fix CVE-2020-14215, you need to update Zulip Server to version 2.1.5 or later.
You can find more information about CVE-2020-14215 in the Zulip Blog post: https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release/