← Back

CVE-2017-0896

nvd nist
Published: Jun 2, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.

Affected (19)

Products: Zulip: Zulip Server
1 product
Zulip Server
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Zulip
Version 1.3.0
Version 1.3.10
Version 1.3.11
Version 1.3.12
Version 1.3.13
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.6
Version 1.3.7
Version 1.3.8
Version 1.3.9
Version 1.4.0
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.5.0
Version 1.5.1

References (6)

Source: support@hackerone.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.