First published: Wed Apr 14 2021(Updated: )
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Zulip Server | <3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-30478.
The severity of CVE-2021-30478 is medium with a CVSS score of 4.3.
The affected software version of CVE-2021-30478 is Zulip Server up to version 3.4 (exclusive).
The CWE ID of CVE-2021-30478 is CWE-269.
To fix CVE-2021-30478, update Zulip Server to version 3.4 or higher.