Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0881

Опубликовано: 28 мар. 2017
Источник: debian
EPSS Низкий

Описание

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zulip-serveritppackage

EPSS

Процентиль: 43%
0.00206
Низкий

Связанные уязвимости

CVSS3: 4.3
nvd
почти 9 лет назад

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.

CVSS3: 4.3
github
больше 3 лет назад

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.

EPSS

Процентиль: 43%
0.00206
Низкий