Information exposure through timing discrepancy in Zulip Server - CVE-2022-41914

 

Information exposure through timing discrepancy in Zulip Server - CVE-2022-41914

Published: November 17, 2022


Vulnerability identifier: #VU69404
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-41914
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Zulip Server
Software vendor:
Zulip

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a weak generation mechanism of SCIM bearer tokens. A remote attacker can infer the value of the SCIM bearer token by performing a sophisticated timing analysis on a large number of failing requests. If successful, this would allow the attacker to impersonate the SCIM client for its abilities to read and update user accounts in the Zulip organization.


Remediation

Install updates from vendor's website.

External links