CVE-2017-0910 is a high-severity vulnerability affecting Zulip Server versions prior to 1.7.1. It allows an authenticated user in one realm to create user accounts in other realms on the same server, potentially leading to unauthorized access, data compromise, and denial of service. The CVSS score of 8.8 indicates a network-exploitable vulnerability with low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the FAUCET Risk Score of 68/100 suggests a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.1CPE matchmatch criteria | cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.