Security Advisory

CVE-2017-0910

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-27 16:00:00
Last updated 2024-09-17 01:26:15
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.