Zulip Server 1.5.1 and below suffer from an error in the implementation of the invitebyadmins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.1"
}
]
}