Описание
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a simultaneous access by the user being deactivated may, in rare cases, allow continued access by the deactivated user. A patch is available in version 4.11 on the 4.x branch and version 5.0-rc1 on the 5.x branch. Upgrading to a fixed version will, as a side effect, deactivate any cached sessions that may have been leaked through this bug. There are currently no known workarounds.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0 (включая) до 4.11 (исключая)
cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00204
Низкий
5.4 Medium
CVSS3
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-362
Связанные уязвимости
CVSS3: 5.4
debian
почти 4 года назад
Zulip is an open source group chat application. Starting with version ...
EPSS
Процентиль: 42%
0.00204
Низкий
5.4 Medium
CVSS3
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-362