Lucene search

K
osvGoogleOSV:CVE-2021-30478
HistoryApr 15, 2021 - 12:15 a.m.

CVE-2021-30478

2021-04-1500:15:13
Google
osv.dev
6
zulip server
permission
bug
system bot
organization

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for OSV:CVE-2021-30478