漏洞标题
通过Zlip服务器的图像代理绕过的IP地址泄漏
漏洞描述信息
Zulip Server中的图片代理绕过导致IP地址泄露
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
IP address leak via image proxy bypass in Zulip Server
漏洞描述信息
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who can send messages could include a crafted URL that tricks the server into embedding a remote image reference directly. This could allow the attacker to infer the viewer’s IP address and browser fingerprinting information. This vulnerability is fixed in Zulip Server 5.6. Zulip organizations with image and link previews [disabled](https://zulip.com/help/allow-image-link-previews) are not affected.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
解释冲突
漏洞标题
Zulip 安全漏洞
漏洞描述信息
Zulip是Zulip团队的一款功能强大的开源群聊应用程序。用于将实时聊天的即时性与线程对话的生产力优势相结合。 Zulip存在安全漏洞,该漏洞源于可以发送消息的攻击者可以发送一个精心制作的URL欺骗服务器直接嵌入远程图像引用,导致攻击者推断查看者的IP地址和浏览器指纹信息。
CVSS信息
N/A
漏洞类别
其他