Medium severity6.5NVD Advisory· Published Jun 2, 2017· Updated May 13, 2026
CVE-2017-0896
CVE-2017-0896
Description
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.
Affected products
20- Zulip/Zulip Serverv5Range: 1.5.1 and below
cpe:2.3:a:zulip:zulip_server:1.3.0:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:zulip:zulip_server:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.11:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.12:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.3.13:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:zulip:zulip_server:1.5.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/zulip/zulip/commit/1f48fa27672170bba3b9a97384905bb04c18761bnvdIssue TrackingPatch
- hackerone.com/reports/224210nvdPermissions Required
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.