Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45v2-23j7-x684

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

EPSS

Процентиль: 46%
0.00231
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

CVSS3: 4.3
debian
почти 5 лет назад

An issue was discovered in Zulip Server before 3.4. A bug in the imple ...

EPSS

Процентиль: 46%
0.00231
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732