Description


An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.

Related CPE's


Weaknesses



CWE-269

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-04-14T22:15:13.170Z

4 years ago

Last modified

2024-11-21T05:04:00.430Z

1 year ago