First published: Fri Aug 21 2020(Updated: )
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-15070.
The severity of CVE-2020-15070 is high with a severity value of 8.8.
Zulip Server 2.x versions up to but excluding 2.1.7 are affected by CVE-2020-15070.
CVE-2020-15070 allows eval injection if a privileged attacker is able to write directly to the PostgreSQL database and craft a custom profile field value.
To fix CVE-2020-15070, update to Zulip Server version 2.1.7 or later.