First published: Mon Aug 29 2022(Updated: )
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Desktop | <27.190 | |
Zulip Desktop | <27.190 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35962 is a vulnerability in Zulip Mobile where a crafted link in a message could lead to credential disclosure.
CVE-2022-35962 affects Zulip Mobile versions up to exclusive 27.189.
CVE-2022-35962 has a severity rating of 5.7 (high).
You can fix CVE-2022-35962 by updating Zulip Mobile to version 27.190 or later.
You can find more information about CVE-2022-35962 on the Zulip blog and Zulip Mobile GitHub page.