CVE-2017-0881

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-03-28 02:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-0881

Mitre link : CVE-2017-0881

CVE.ORG link : CVE-2017-0881


JSON object : View

Products Affected

zulip

  • zulip_server
CWE
CWE-863

Incorrect Authorization

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor