Description
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/zulip/zulip-mobile/security/advisories/GHSA-4gj2-j32x-4wg5
Release Notes, Vendor Advisory x_refsource_misc
https://blog.zulip.com/2022/08/24/zulip-server-5-6-security-release/
Third Party Advisory x_refsource_misc
https://github.com/zulip/zulip-mobile/releases/tag/v27.190
Scores
CVSS v3
8.0
EPSS
0.0086
EPSS Percentile
53.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-184
CWE-697
CWE-436
Status
published
Products (1)
zulip/zulip
< 27.190 (2 CPE variants)
Published
Aug 29, 2022
Tracked Since
Feb 18, 2026