4.9

CVE-2022-31134

Zulip Server public data export contains attachments that are non-public

Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to administrators, in many configurations server administrators are not expected to have access to private messages and private streams. However, the "public data" export which administrators could generate contained the attachment contents for all attachments, even those from private messages and streams. Zulip Server version 5.4 contains a patch for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZulipZulip Server Version >= 2.1.0 < 5.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.87% 0.553
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
security-advisories@github.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://blog.zulip.com/2022/07/12/zulip-cloud-data-exports
Vendor Advisory
https://blog.zulip.com/2022/07/12/zulip-server-5-4-security-release
Vendor Advisory
Release Notes
https://github.com/zulip/zulip/security/advisories/GHSA-58pm-88xp-7x9m
Third Party Advisory
Release Notes