Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique works for creating private channels without permission, though such a process requires either the API or modifying the HTML, as we do mark the "private" radio button as disabled in such cases. Version 10.3 contains a patch.
References
Configurations
History
27 Aug 2025, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/zulip/zulip/commit/d2ff4bda4c3efa30fc3ab1f151255cfdbf370f78 - Patch | |
References | () https://github.com/zulip/zulip/security/advisories/GHSA-rqg7-xfqg-v7q5 - Third Party Advisory | |
References | () https://zulip.com/help/configure-who-can-create-channels - Product | |
References | () https://zulip.readthedocs.io/en/latest/overview/changelog.html#zulip-server-10-3 - Release Notes | |
First Time |
Zulip zulip
Zulip |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:* |
16 May 2025, 14:42
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-16 00:15
Updated : 2025-08-27 02:26
NVD link : CVE-2025-47930
Mitre link : CVE-2025-47930
CVE.ORG link : CVE-2025-47930
JSON object : View
Products Affected
zulip
- zulip
CWE
CWE-863
Incorrect Authorization