CVE-2024-36612

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*

History

09 Apr 2025, 18:54

Type Values Removed Values Added
CPE cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*
First Time Zulip
Zulip zulip Server
References () https://gist.github.com/1047524396/f7ff51d24ebbb29e21dfb70a0c97302b - () https://gist.github.com/1047524396/f7ff51d24ebbb29e21dfb70a0c97302b - Third Party Advisory
References () https://github.com/zulip/zulip/blob/8.3/web/src/click_handlers.js - () https://github.com/zulip/zulip/blob/8.3/web/src/click_handlers.js - Product
References () https://github.com/zulip/zulip/commit/0a90a13becbf0338a8fc1ad37946e51c2c25b0a5 - () https://github.com/zulip/zulip/commit/0a90a13becbf0338a8fc1ad37946e51c2c25b0a5 - Patch

Information

Published : 2024-11-29 20:15

Updated : 2025-04-09 18:54


NVD link : CVE-2024-36612

Mitre link : CVE-2024-36612

CVE.ORG link : CVE-2024-36612


JSON object : View

Products Affected

zulip

  • zulip_server
CWE
CWE-125

Out-of-bounds Read