Skip to content

Invalid metadata access for formerly subscribed streams.

Moderate
alexmv published GHSA-c9wc-65fh-9x8p Nov 16, 2023

Package

Zulip Server (Application)

Affected versions

1.3.0 through 7.4

Patched versions

7.5

Description

It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had been removed from a stream, but still had an account in the organization, could still view metadata for that stream (including the stream name, description, settings, and an email address used to send emails into the stream via the incoming email integration). This potentially allowed users to see changes to a stream’s metadata after they had lost access to the stream.

This bug was present in all Zulip releases prior to today's Zulip Server 7.5.

Severity

Moderate
4.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2023-47642

Weaknesses

No CWEs