Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-0881

Опубликовано: 28 мар. 2017
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*
Версия до 1.4.3 (исключая)

EPSS

Процентиль: 43%
0.00206
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 4.3
debian
почти 9 лет назад

An error in the implementation of an autosubscribe feature in the chec ...

CVSS3: 4.3
github
больше 3 лет назад

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.

EPSS

Процентиль: 43%
0.00206
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-863