{"id":"CVE-2017-0881","details":"An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.","modified":"2026-08-07T14:48:39.192848Z","published":"2017-03-28T02:59:01.463Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97159"},{"type":"FIX","url":"https://github.com/zulip/zulip/commit/7ecda1ac8e26d8fb3725e954b2dc4723dda2255f"},{"type":"FIX","url":"https://groups.google.com/d/msg/zulip-announce/VyawgRuoY34/NTBwnTArGwAJ"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zulip/zulip","events":[{"introduced":"0"},{"fixed":"a063dd3b26f7ada794e14ace0d24ea1834611446"},{"fixed":"7ecda1ac8e26d8fb3725e954b2dc4723dda2255f"}],"database_specific":{"cpe":"cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.4.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.4.2","1.4.1","1.4.0","1.3.13","1.3.11","1.3.10","1.3.9","1.3.8","1.3.7","1.3.6","1.3.5","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","enterprise-1.2.0","enterprise-1.1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-0881.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}