Page 4 of 54 results (0.038 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación de la funcionalidad API all_public_streams resultó en que usuarios invitados pudieran recibir tráfico de mensajes a transmisiones públicas que s... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 • CWE-269: Improper Privilege Management •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación del permiso can_forge_sender (anteriormente es_api_super_user) hizo a unos usuarios con e... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 • CWE-269: Improper Privilege Management •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación de las respuestas a los mensajes enviados por webhooks salientes a transmisiones privadas significaba que un bot web... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 •

CVSS: 4.0EPSS: 0%CPEs: 1EXPL: 0

14 Apr 2021 — In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation. En el tema de mover API en Zulip Server versiones 3.x anteriores a 3.4, unos administradores de la organización pudieron mover mensajes a transmisiones en otras organizaciones alojadas por la misma instalación de Zulip • https://blog.zulip.com/2021/04/14/zulip-server-3-4 •

CVSS: 9.8EPSS: 2%CPEs: 1EXPL: 0

05 Feb 2021 — Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. Zulip Desktop versiones anteriores a 5.0.0, usa inapropiadamente shell.openExternal y shell.openItem con contenido que no es confiable, conllevando a una ejecución de código remota • https://blog.zulip.com/2020/04/01/zulip-desktop-5-0-0-security-release •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

05 Feb 2021 — Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. Zulip Desktop versiones anteriores a 5.0.0, permite a atacantes llevar a cabo grabaciones por medio de la cámara web y el micrófono debido a una falta de un gestor de peticiones de permisos • https://blog.zulip.com/2020/04/01/zulip-desktop-5-0-0-security-release • CWE-862: Missing Authorization •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. Zulip Server versiones anteriores a 2.1.5, permite un ataque de tipo XSS reflejado por medio de un webhook de Dropbox. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.8EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. Zulip Server versiones anteriores a 2.1.5, permite tabnapping inverso por medio de un enlace de encabezado de tema. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-269: Improper Privilege Management •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. Zulip Server versiones anteriores a 2.1.5, presenta un Control de Acceso Incorrecto porque la función 0198_preregistrationuser_invited_as agrega el papel de administrador a las invitaciones. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-269: Improper Privilege Management •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

21 Aug 2020 — Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value. Zulip Server versiones 2.x anteriores a 2.1.7, permite una inyección eval si un atacante privilegiado era capaz de escribir directamente en la base de datos de postgres y eligió escribir un valor diseñado del campo de perfil personalizado. • https://blog.zulip.com/2020/06/26/zulip-server-2-1-7-security-release • CWE-94: Improper Control of Generation of Code ('Code Injection') •