Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18933

Опубликовано: 21 нояб. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 2.0.7 (исключая)

EPSS

Процентиль: 62%
0.00431
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
debian
около 6 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new ...

CVSS3: 9.8
github
больше 3 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

EPSS

Процентиль: 62%
0.00431
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo