Логотип exploitDog
bind:CVE-2019-18933
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-18933

Количество 3

Количество 3

nvd логотип

CVE-2019-18933

около 6 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-18933

около 6 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8c73-4mfq-f8m8

больше 3 лет назад

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-18933

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

CVSS3: 9.8
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-18933

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new ...

CVSS3: 9.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-8c73-4mfq-f8m8

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу