Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24751

Опубликовано: 16 мар. 2022
Источник: nvd
CVSS3: 5.4
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a simultaneous access by the user being deactivated may, in rare cases, allow continued access by the deactivated user. A patch is available in version 4.11 on the 4.x branch and version 5.0-rc1 on the 5.x branch. Upgrading to a fixed version will, as a side effect, deactivate any cached sessions that may have been leaked through this bug. There are currently no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.11 (исключая)

EPSS

Процентиль: 42%
0.00204
Низкий

5.4 Medium

CVSS3

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.4
debian
почти 4 года назад

Zulip is an open source group chat application. Starting with version ...

EPSS

Процентиль: 42%
0.00204
Низкий

5.4 Medium

CVSS3

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-362