Skip to content

Cross-site scripting vulnerabilities in HTML string interpolation

Moderate
andersk published GHSA-h968-w54f-x5q7 Oct 27, 2020

Package

No package listed

Affected versions

5.4.2 and earlier

Patched versions

5.4.3

Description

Zulip Desktop failed to escape various strings interpolated into the user interface HTML. This could result in code execution when connecting to a maliciously altered Zulip server.

The Zulip security team discovered this issue during internal auditing. Zulip Desktop versions 5.4.2 and earlier are affected.

Severity

Moderate

CVE ID

CVE-2020-24582

Weaknesses

No CWEs