#VU65858 Improper access control in Zulip Server - CVE-2017-0881
Published: July 28, 2022
Zulip Server
Zulip
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the autosubscribe feature in the check_stream_exists route of the Zulip group chat application server. A remote user can bypass implemented security restrictions and subscribe to a private stream without the necessary invitation from the group member.