漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Zulip allows the deletion of Custom profile fields by administrators of a different organization
Vulnerability Description
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete custom profile fields belonging to a different organization. This is fixed in Zulip Server 10.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
通过用户控制SQL主密钥绕过授权机制
Vulnerability Title
Zulip server 安全漏洞
Vulnerability Description
Zulip server是美国Zulip公司的一款开源的团队聊天应用程序。 Zulip server 10.1之前版本存在安全漏洞,该漏洞源于删除组织自定义配置文件字段API中的权限检查不足,可能导致管理员删除其他组织的自定义配置文件字段。
CVSS Information
N/A
Vulnerability Type
N/A