Improper access control in Zulip Server - CVE-2023-47642

 

Improper access control in Zulip Server - CVE-2023-47642

Published: November 17, 2023


Vulnerability identifier: #VU83257
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-47642
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. Active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream after they were removed from the stream.


Affected software

Zulip Server

How to mitigate CVE-2023-47642

Install updates from vendor's website.

Zulip Server - update to 7.5

External References

Related Security Bulletins