CVE-2023-33186
- EPSS 0.25%
- Published 30.05.2023 06:16:36
- Last modified 21.11.2024 08:05:04
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, includin...
CVE-2023-22735
- EPSS 0.24%
- Published 07.02.2023 19:15:09
- Last modified 21.11.2024 07:45:19
Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` which would be served from the Zulip hostname with `Content-Disposition:...
CVE-2022-41914
- EPSS 0.11%
- Published 16.11.2022 20:15:10
- Last modified 21.11.2024 07:24:03
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did not run in co...
CVE-2022-31134
- EPSS 0.4%
- Published 12.07.2022 21:15:09
- Last modified 21.11.2024 07:03:58
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is o...
CVE-2022-23656
- EPSS 0.32%
- Published 02.03.2022 21:15:08
- Last modified 21.11.2024 06:49:02
Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could maliciously craft a full name for their a...
CVE-2022-21706
- EPSS 0.14%
- Published 26.02.2022 00:15:08
- Last modified 21.11.2024 06:45:16
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is...
CVE-2021-30478
- EPSS 0.14%
- Published 15.04.2021 00:15:13
- Last modified 21.11.2024 06:04:00
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot,...
- EPSS 0.21%
- Published 15.04.2021 00:15:13
- Last modified 21.11.2024 06:04:01
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.
CVE-2021-30479
- EPSS 0.2%
- Published 15.04.2021 00:15:13
- Last modified 21.11.2024 06:04:00
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of ...
CVE-2021-30477
- EPSS 0.23%
- Published 15.04.2021 00:15:13
- Last modified 21.11.2024 06:04:00
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was...