Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Zulip Server has access control bypass for restrictions on creation of specific channel types
Vulnerability Description
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique works for creating private channels without permission, though such a process requires either the API or modifying the HTML, as we do mark the "private" radio button as disabled in such cases. Version 10.3 contains a patch.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Zulip 安全漏洞
Vulnerability Description
Zulip是美国Zulip公司的一款功能强大的开源群聊应用程序。用于将实时聊天的即时性与线程对话的生产力优势相结合。 Zulip 10.0至10.3之前版本存在安全漏洞,该漏洞源于可绕过通道创建权限控制机制,可能导致未经授权的通道创建。
CVSS Information
N/A
Vulnerability Type
N/A