Lucene search

K
osvGoogleOSV:CVE-2021-30477
HistoryApr 15, 2021 - 12:15 a.m.

CVE-2021-30477

2021-04-1500:15:13
Google
osv.dev
6
zulip server
unauthorized messages
private streams
outgoing webhooks

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for OSV:CVE-2021-30477