Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-30477

Опубликовано: 15 апр. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*
Версия до 3.4 (исключая)

EPSS

Процентиль: 46%
0.00231
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
debian
почти 5 лет назад

An issue was discovered in Zulip Server before 3.4. A bug in the imple ...

CVSS3: 4.3
github
больше 3 лет назад

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

EPSS

Процентиль: 46%
0.00231
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

NVD-CWE-noinfo