Back to search
CVE-2017-0896
Published: Jun 2, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.
| Vendor | Product | Versions |
|---|---|---|
Zulip | Zulip Server | affected 1.5.1 and below |
Weaknesses (CWE)
References
[zulip-announce] 20170601 Zulip Server 1.5.2 released
mailing-list
x_refsource_MLIST
https://hackerone.com/reports/224210
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now