Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18933

Опубликовано: 21 нояб. 2019
Источник: debian
EPSS Низкий

Описание

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zulip-serveritppackage

EPSS

Процентиль: 62%
0.00431
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

CVSS3: 9.8
github
больше 3 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

EPSS

Процентиль: 62%
0.00431
Низкий