Live data from Hacker News

Zulip Cloud security vulnerability with reusable invitation links

blog.zulip.com

1–10 of 38 posts

Re: Zulip Cloud security vulnerability with reusable invitation links

#3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2170...

> Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack where an invitation created in one organization (potentially as a role with elevated permissions) can be used to join any other organization. This bypasses any restrictions on required domains on users' email addresses, may be used to gain access to organizations which are only accessible by invitation, and may be used to gain access with elevated privileges. This issue has been patched in release 4.10.

Why does it feel like the completely misleading title was intentional to try and drive traffic to / SEO this crappy copycat CVE site?

Re: Zulip Cloud security vulnerability with reusable invitation links

#6

Is anyone using Zulip and has it made a difference to Slack for example?

Clojurians-Zulip is much better interface to catch up and read through existing information than Clojurians-Slack ever was (Clojurians is basically bunch of Clojure(Script) people helping/getting help from each other), for whats it worth. Best would be if they both could be fully public, but for now the archives seems to do the job well at least.

Re: Zulip Cloud security vulnerability with reusable invitation links

#9
Zulip in Docker¶

Zulip has an officially supported, experimental docker image. Please note that Zulip’s normal installer has been extremely reliable for years, whereas the Docker image is new and has rough edges, so we recommend the normal installer unless you have a specific reason to prefer Docker. [0]

A server application without Helm charts? Stateful apps without Kubernetes Operator? For someone living with k8s all day, it feels so strange to need to make a VM, update it, then follow the installation steps and then for years coming having to keep them updated, migrate to new hosts, etc, etc.

[0] https://zulip.readthedocs.io/en/stable/production/deployment...

Post reply on HN