An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-04-14T23:48:38

Updated: 2021-04-14T23:48:38

Reserved: 2021-04-09T00:00:00


Link: CVE-2021-30479

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-04-15T00:15:13.170

Modified: 2022-07-12T17:42:04.277


Link: CVE-2021-30479

JSON object: View

cve-icon Redhat Information

No data.

CWE