Vulnerabilities > CVE-2017-0881 - Incorrect Authorization vulnerability in Zulip Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.securityfocus.com/bid/97159
- http://www.securityfocus.com/bid/97159
- https://github.com/zulip/zulip/commit/7ecda1ac8e26d8fb3725e954b2dc4723dda2255f
- https://github.com/zulip/zulip/commit/7ecda1ac8e26d8fb3725e954b2dc4723dda2255f
- https://groups.google.com/d/msg/zulip-announce/VyawgRuoY34/NTBwnTArGwAJ
- https://groups.google.com/d/msg/zulip-announce/VyawgRuoY34/NTBwnTArGwAJ