Lucene search

K
cvelistMitreCVELIST:CVE-2019-18933
HistoryNov 21, 2019 - 10:45 p.m.

CVE-2019-18933

2019-11-2122:45:15
mitre
www.cve.org
4

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

64.7%

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user’s account.

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

64.7%

Related for CVELIST:CVE-2019-18933