6.5

CVE-2017-0896

Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.

Data is provided by the National Vulnerability Database (NVD)
ZulipZulip Server Version1.3.0
ZulipZulip Server Version1.3.1
ZulipZulip Server Version1.3.2
ZulipZulip Server Version1.3.3
ZulipZulip Server Version1.3.4
ZulipZulip Server Version1.3.6
ZulipZulip Server Version1.3.7
ZulipZulip Server Version1.3.8
ZulipZulip Server Version1.3.9
ZulipZulip Server Version1.3.10
ZulipZulip Server Version1.3.11
ZulipZulip Server Version1.3.12
ZulipZulip Server Version1.3.13
ZulipZulip Server Version1.4.0
ZulipZulip Server Version1.4.1
ZulipZulip Server Version1.4.2
ZulipZulip Server Version1.4.3
ZulipZulip Server Version1.5.0
ZulipZulip Server Version1.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.36
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.