CVE Vulnerabilities

CVE-2021-30487

Published: Apr 15, 2021 | Modified: Jul 12, 2022
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.

Affected Software

Name Vendor Start Version End Version
Zulip_server Zulip 3.0 (including) 3.4 (excluding)

References