Vulnerability Details CVE-2019-18933
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-18933
-
cpe:2.3:a:zulip:zulip_server:1.7.0
-
cpe:2.3:a:zulip:zulip_server:1.7.1
-
cpe:2.3:a:zulip:zulip_server:1.7.2
-
cpe:2.3:a:zulip:zulip_server:1.8.0
-
cpe:2.3:a:zulip:zulip_server:1.8.1
-
cpe:2.3:a:zulip:zulip_server:1.9.0
-
cpe:2.3:a:zulip:zulip_server:1.9.1
-
cpe:2.3:a:zulip:zulip_server:1.9.2
-
cpe:2.3:a:zulip:zulip_server:2.0.0
-
cpe:2.3:a:zulip:zulip_server:2.0.1
-
cpe:2.3:a:zulip:zulip_server:2.0.2
-
cpe:2.3:a:zulip:zulip_server:2.0.3
-
cpe:2.3:a:zulip:zulip_server:2.0.4
-
cpe:2.3:a:zulip:zulip_server:2.0.5
-
cpe:2.3:a:zulip:zulip_server:2.0.6