Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8837 | Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 Aug 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zulip:zulip:10.0:*:*:*:*:*:*:* |
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of any organization was incorrectly allowed to delete an export of a different organization. This is fixed in Zulip Server 10.1. | |
| Title | Zulip allows the deletion of organization by administrators of a different organization | |
| Weaknesses | CWE-566 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-31T18:59:32.854Z
Reserved: 2025-03-21T14:12:06.271Z
Link: CVE-2025-30368
Updated: 2025-03-31T18:59:26.347Z
Status : Analyzed
Published: 2025-03-31T17:15:42.320
Modified: 2025-08-27T01:51:53.017
Link: CVE-2025-30368
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:05Z
EUVD