High severity8.8NVD Advisory· Published Nov 27, 2017· Updated May 13, 2026
CVE-2017-0910
CVE-2017-0910
Description
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
Affected products
2- Zulip/Zulip Serverv5Range: before 1.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32nvdPatchThird Party Advisory
- blog.zulip.org/2017/11/23/zulip-1-7-1-released/nvdVendor Advisory
News mentions
0No linked articles in our index yet.