First published: Wed Apr 14 2021(Updated: )
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-30477.
CVE-2021-30477 has a severity rating of 4.3 (medium).
The affected software of CVE-2021-30477 is Zulip Server before version 3.4.
CVE-2021-30477 is a vulnerability in Zulip Server that allows outgoing webhook bots to send messages to private streams they are not supposed to.
To fix CVE-2021-30477, you should update Zulip Server to version 3.4 or later.