SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-35962

In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link.

MEDIUM 5.7EPSS 1.09%

Does this matter?

Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.

Description

Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.

CVSS 3.1
5.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS
1.09% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-184, CWE-436, CWE-697
Affected
zulip/zulip
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.