CVE-2022-24751
Race condition in Zulip
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a simultaneous access by the user being deactivated may, in rare cases, allow continued access by the deactivated user. A patch is available in version 4.11 on the 4.x branch and version 5.0-rc1 on the 5.x branch. Upgrading to a fixed version will, as a side effect, deactivate any cached sessions that may have been leaked through this bug. There are currently no known workarounds.
Zulip es una aplicación de chat de grupo de código abierto. A partir de la versión 4.0 y versiones anteriores a 4.11, Zulip es vulnerable a una condición de carrera durante la deshabilitación de la cuenta, donde un acceso simultáneo por parte del usuario que está siendo deshabilitado puede, en raros casos, permitir el acceso continuo por parte del usuario deshabilitado. Se presenta un parche disponible en versión 4.11 en la rama 4.x y en versión 5.0-rc1 en la rama 5.x. Una actualización a una versión corregida deshabilitará, como efecto secundario, cualquier sesión en caché que pueda haberse filtrado mediante este bug. Actualmente no se presentan medidas de mitigación conocidas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-03-16 CVE Published
- 2024-08-03 CVE Updated
- 2025-04-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/zulip/zulip/security/advisories/GHSA-6v98-m5x5-phqj | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/zulip/zulip/commit/62ba8e455d8f460001d9fb486a6dabfd1ed67717 | 2022-03-22 | |
https://github.com/zulip/zulip/commit/e6eace307ef435eec3395c99247155efed9219e4 | 2022-03-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zulip Search vendor "Zulip" | Zulip Search vendor "Zulip" for product "Zulip" | >= 4.0 < 4.11 Search vendor "Zulip" for product "Zulip" and version " >= 4.0 < 4.11" | - |
Affected
|