CVE-2022-35962
HIGHZulip Mobile <27.189 - Info Disclosure
Title source: llmDescription
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in version 27.190.
Scores
CVSS v3
8.0
EPSS
0.0054
EPSS Percentile
67.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-184
CWE-697
CWE-436
Status
published
Affected Products (2)
zulip/zulip
< 27.190
zulip/zulip
< 27.190
Timeline
Published
Aug 29, 2022
Tracked Since
Feb 18, 2026