Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-30369

Опубликовано: 31 мар. 2025
Источник: debian
EPSS Низкий

Описание

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete custom profile fields belonging to a different organization. This is fixed in Zulip Server 10.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zulip-serveritppackage

EPSS

Процентиль: 42%
0.00199
Низкий

Связанные уязвимости

CVSS3: 2.7
nvd
10 месяцев назад

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete custom profile fields belonging to a different organization. This is fixed in Zulip Server 10.1.

EPSS

Процентиль: 42%
0.00199
Низкий