Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-47642— Stream description leaks to ex-subscribers in Zulip

CVSS 4.3 · Medium EPSS 0.48% · P39

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-47642

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stream description leaks to ex-subscribers in Zulip
Source: CVE Program / CVE List V5
Vulnerability Description
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had been removed from a stream, but still had an account in the organization, could still view metadata for that stream (including the stream name, description, settings, and an email address used to send emails into the stream via the incoming email integration). This potentially allowed users to see changes to a stream’s metadata after they had lost access to the stream. This vulnerability has been addressed in version 7.5 and all users are advised to upgrade. There are no known workarounds for this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Zulip 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zulip是美国Zulip公司的一款功能强大的开源群聊应用程序。用于将实时聊天的即时性与线程对话的生产力优势相结合。 Zulip 7.5版本存在安全漏洞,该漏洞源于之前错误订阅流的活跃用户仍然能够使用Zulip API访问该流的元数据,允许用户在失去对流的访问权限后查看流元数据的更改。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
zulipzulip >= 1.3.0, < 7.5 -

II. Public POCs for CVE-2023-47642

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-47642

登录查看更多情报信息。

Patches & Fixes for CVE-2023-47642 (1)

Vendor Advisories for CVE-2023-47642 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-47642

No comments yet


Leave a comment