Description
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-1253 | In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm. |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T01:26:15.105Z
Reserved: 2016-11-30T00:00:00.000Z
Link: CVE-2017-0910
No data.
Status : Modified
Published: 2017-11-27T16:29:00.217
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-0910
No data.
OpenCVE Enrichment
No data.
EUVD