CVE-2025-47930

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47930
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47930.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47930
Aliases
  • GHSA-rqg7-xfqg-v7q5
Published
2025-05-16T00:15:18Z
Modified
2025-05-20T03:27:12.388154Z
Summary
[none]
Details

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique works for creating private channels without permission, though such a process requires either the API or modifying the HTML, as we do mark the "private" radio button as disabled in such cases. Version 10.3 contains a patch.

References

Affected packages

Git / github.com/zulip/zulip

Affected ranges

Type
GIT
Repo
https://github.com/zulip/zulip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
1.8.0-rc1
1.9.0
1.9.0-rc2
1.9.0-rc3

10.*

10.0
10.0-beta1
10.0-beta2
10.0-dev

2.*

2.0.0
2.0.0-rc1
2.1-dev
2.1.0
2.1.0-rc1
2.2-dev

3.*

3.0
3.0-dev
3.0-rc1
3.0-rc2

4.*

4.0
4.0-dev

5.*

5.0
5.0-dev

6.*

6.0
6.0-dev

7.*

7.0
7.0-beta3
7.0-dev

8.*

8.0
8.0-beta1
8.0-beta2
8.0-dev

9.*

9.0
9.0-beta1
9.0-dev

enterprise-1.*

enterprise-1.1.5
enterprise-1.2.0

shared-0.*

shared-0.0.1
shared-0.0.10
shared-0.0.11
shared-0.0.12
shared-0.0.13
shared-0.0.14
shared-0.0.15
shared-0.0.16
shared-0.0.17
shared-0.0.18
shared-0.0.2
shared-0.0.3
shared-0.0.4
shared-0.0.5
shared-0.0.6
shared-0.0.7
shared-0.0.8
shared-0.0.9