VulnerabilityModified
CVE-2022-35962
In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link.
MEDIUM 5.7EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.
- CVSS 3.1
- 5.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-184, CWE-436, CWE-697
- Affected
- zulip/zulip
- Source
- security-advisories@github.com
References
- https://blog.zulip.com/2022/08/24/zulip-server-5-6-security-release/Release Notes, Vendor Advisory
- https://github.com/zulip/zulip-mobile/releases/tag/v27.190Third Party Advisory
- https://github.com/zulip/zulip-mobile/security/advisories/GHSA-4gj2-j32x-4wg5Third Party Advisory
- https://blog.zulip.com/2022/08/24/zulip-server-5-6-security-release/Release Notes, Vendor Advisory
- https://github.com/zulip/zulip-mobile/releases/tag/v27.190Third Party Advisory
- https://github.com/zulip/zulip-mobile/security/advisories/GHSA-4gj2-j32x-4wg5Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.