#VU83257 Improper access control in Zulip Server - CVE-2023-47642

 

#VU83257 Improper access control in Zulip Server - CVE-2023-47642

Published: November 17, 2023


Vulnerability identifier: #VU83257
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-47642
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Zulip Server
Software vendor:
Zulip

Description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. Active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream after they were removed from the stream.


Remediation

Install updates from vendor's website.

External links