Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31134

Опубликовано: 12 июл. 2022
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to administrators, in many configurations server administrators are not expected to have access to private messages and private streams. However, the "public data" export which administrators could generate contained the attachment contents for all attachments, even those from private messages and streams. Zulip Server version 5.4 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*
Версия от 2.1.0 (включая) до 5.4 (исключая)

EPSS

Процентиль: 60%
0.00401
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-434

Связанные уязвимости

CVSS3: 4.9
debian
больше 3 лет назад

Zulip is an open-source team collaboration tool. Zulip Server versions ...

EPSS

Процентиль: 60%
0.00401
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-434