CVE-2017-0896: Zulip Server
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.
Affected products
- Zulip Zulip Server: version 1.3.0 only; version 1.3.1 only; version 1.3.2 only; version 1.3.3 only; version 1.3.4 only; version 1.3.6 only; …
Published 2017-06-02. Last modified 2026-06-17.