{"id":"CVE-2017-0910","details":"In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.","modified":"2026-08-07T14:48:39.456478Z","published":"2017-11-27T16:29:00.217Z","references":[{"type":"ADVISORY","url":"http://blog.zulip.org/2017/11/23/zulip-1-7-1-released/"},{"type":"FIX","url":"https://github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zulip/zulip","events":[{"introduced":"0"},{"fixed":"2e4ae9c5dcc8a759ededdf5e745a2862b4516de2"},{"fixed":"960d736e55cbb9386a68e4ee45f80581fd2a4e32"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.7.1"}]}}],"versions":["1.7.0","1.6.0","1.5.0","1.4.0","1.3.13","1.3.11","1.3.10","1.3.9","1.3.8","1.3.7","1.3.6","1.3.5","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","enterprise-1.2.0","enterprise-1.1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-0910.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}