Vulnerabilities
Vulnerable Software
Zulip:  >> Zulip  >> 10.1.70  Security Vulnerabilities
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique works for creating private channels without permission, though such a process requires either the API or modifying the HTML, as we do mark the "private" radio button as disabled in such cases. Version 10.3 contains a patch.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-05-16
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.
CVSS Score
8.0
EPSS Score
0.005
Published
2022-08-29


Contact Us

Shodan ® - All rights reserved