
CVE-2023-47642 – Stream description leaks to ex-subscribers in Zulip
https://notcve.org/view.php?id=CVE-2023-47642
16 Nov 2023 — Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had been removed from a stream, but still had an account in the organization, could still view metadata for that stream (including the stream name, description, settings, and an email address used to send emails into the stream via the i... • https://github.com/zulip/zulip/commit/6336322d2f9bbccaacfc80cba83a3c62eefd5737 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2023-32678 – Zulip vulnerable to insufficient authorization check for edition/deletion of messages and topics in private streams by former subscribers
https://notcve.org/view.php?id=CVE-2023-32678
25 Aug 2023 — Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete messages that they used to have access to, if other relevant organization permissions allow these actions. For example, a user may be able to edit or delete their old messages they posted in such a private stream. An administrator w... • https://github.com/zulip/zulip/security/advisories/GHSA-q3wg-jm9p-35fj • CWE-285: Improper Authorization •

CVE-2021-30479
https://notcve.org/view.php?id=CVE-2021-30479
14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación de la funcionalidad API all_public_streams resultó en que usuarios invitados pudieran recibir tráfico de mensajes a transmisiones públicas que s... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 • CWE-269: Improper Privilege Management •

CVE-2021-30478
https://notcve.org/view.php?id=CVE-2021-30478
14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación del permiso can_forge_sender (anteriormente es_api_super_user) hizo a unos usuarios con e... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 • CWE-269: Improper Privilege Management •

CVE-2021-30477
https://notcve.org/view.php?id=CVE-2021-30477
14 Apr 2021 — An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to. Se detectó un problema en Zulip Server versiones anteriores a 3.4. Un bug en la implementación de las respuestas a los mensajes enviados por webhooks salientes a transmisiones privadas significaba que un bot web... • https://blog.zulip.com/2021/04/14/zulip-server-3-4 •

CVE-2020-12759
https://notcve.org/view.php?id=CVE-2020-12759
21 Aug 2020 — Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. Zulip Server versiones anteriores a 2.1.5, permite un ataque de tipo XSS reflejado por medio de un webhook de Dropbox. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-14194
https://notcve.org/view.php?id=CVE-2020-14194
21 Aug 2020 — Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. Zulip Server versiones anteriores a 2.1.5, permite tabnapping inverso por medio de un enlace de encabezado de tema. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-269: Improper Privilege Management •

CVE-2020-14215
https://notcve.org/view.php?id=CVE-2020-14215
21 Aug 2020 — Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. Zulip Server versiones anteriores a 2.1.5, presenta un Control de Acceso Incorrecto porque la función 0198_preregistrationuser_invited_as agrega el papel de administrador a las invitaciones. • https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release • CWE-269: Improper Privilege Management •

CVE-2020-15070
https://notcve.org/view.php?id=CVE-2020-15070
21 Aug 2020 — Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value. Zulip Server versiones 2.x anteriores a 2.1.7, permite una inyección eval si un atacante privilegiado era capaz de escribir directamente en la base de datos de postgres y eligió escribir un valor diseñado del campo de perfil personalizado. • https://blog.zulip.com/2020/06/26/zulip-server-2-1-7-security-release • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2020-9445
https://notcve.org/view.php?id=CVE-2020-9445
20 Apr 2020 — Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality. El servidor Zulip versiones anteriores a 2.1.3, permite un ataque de tipo XSS por medio de la característica modal_link en la funcionalidad Markdown. • https://blog.zulip.org/2020/04/01/zulip-server-2-1-3-security-release • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •