Latest Zulip Vulnerabilities

Zulip non-admins can invite new users to streams they would not otherwise be able to add existing users to
Zulip Zulip Server>=1.9.0<6.2
Zulip Zulip Server>=8.0<8.1
Stream description leaks to ex-subscribers in Zulip
Zulip Zulip Server>=1.3.0<7.5
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain ...
Zulip Zulip Server<7.3
Cross-site scripting vulnerability in Zulip Server development branch via topic tooltip
Zulip Zulip Server=7.0-beta1
Zulip Zulip Server=7.0-beta2
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBacken...
Zulip Zulip<6.2
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invit...
Zulip Zulip<6.2
Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` which would be served ...
Zulip Zulip Server=2023-01-09
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bear...
Zulip Zulip Server>=5.0<5.7
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview vi...
Zulip Zulip<5.6
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to ...
Zulip Zulip<27.190
Zulip Zulip<27.190
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
Zulip Zulip<1.3.12
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
Zulip Zulip<1.3.12
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administra...
Zulip Zulip<5.5
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to downl...
Zulip Zulip Server>=2.1.0<5.4
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers ...
Zulip Zulip>=2.1.0<5.3
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a simultaneous access by...
Zulip Zulip>=4.0<4.11
Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attack...
Zulip Zulip Server>=2021-06-03<2022-03-01
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Serve...
Zulip Zulip Server>=2.0.0<4.10.0
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or...
Zulip Zulip<4.9
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
Zulip Zulip<=4.8
Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitat...
Zulip Zulip<4.8
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users s...
Zulip Zulip<4.7
Zulip Zulip Server>=3.0<3.4
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to s...
Zulip Zulip Server<3.4
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to ...
Zulip Zulip Server<3.4
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams th...
Zulip Zulip Server<3.4
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
Zulip Zulip Desktop<5.0.0
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
Zulip Zulip Desktop<5.0.0
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
Zulip Zulip Server<2.1.5
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
Zulip Zulip Server<2.1.5
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Zulip Zulip Server<2.1.5
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
Zulip Zulip Server<2.1.3
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
Zulip Zulip Server<2.1.3
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
Zulip Zulip Server<=2.1.3
Zulip Zulip Server>=1.9.0<2.0.8
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an o...
Zulip Zulip Server>=1.7.0<2.0.7
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attac...
Zulip Zulip Server>=1.8.0<2.0.5
The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server ...
Zulip Zulip Server<2.0.5

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203