Improper Access Control in Zulip Server Allows Guest Users to Access Private Message Traffic

Improper Access Control in Zulip Server Allows Guest Users to Access Private Message Traffic

CVE-2021-30479 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.

Learn more about our Cis Benchmark Audit For Server Software.