#VU60897 Improper access control in Zulip Server - CVE-2022-21706
Published: February 28, 2022
Zulip Server
Zulip
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a reusable invitation link can be used to join a different organization than the one it was created for. A remote user can join an organization without an invitation and gain elevated pririvleges.
Remediation
External links
- https://github.com/zulip/zulip/security/advisories/GHSA-6xmj-2wcm-p2jc
- https://blog.zulip.com/2022/02/25/zulip-cloud-invitation-vulnerability/
- https://github.com/zulip/zulip/commit/88917019f03860609114082cdc0f31a561503f9e
- https://blog.zulip.com/2022/02/25/zulip-server-4-10-security-release/#cve-2022-21706