In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32 | third party advisory patch |
http://blog.zulip.org/2017/11/23/zulip-1-7-1-released/ | vendor advisory |