Vulnerabilities & PatchesEmerging1 src
Issue 199: Vulnerability in Zulip server, broken access controls threat to APIs, introduction to BOLA
This week, we have news of a API vulnerability allowing privilege escalation in the team chat tool Zulip. We also have articles from PortSwigger on the threat of broken access controls and injection attacks to APIs, as well as a quick read on Broken Object Level Authorization vulnerabilities. Finally, we feature a guide from the Cloud Security Alliance on API security best practices.
Vulnerability: Privilege escalation vulnerability in Zulip Server
Security researchers have revealed details of a critical privilege escalation vulnerability in the API of Zulip Server. The vulnerability is tracked as CVE-2022-31168 and affects all versions of Zulip Server up to 5. 4. Users are recommended to upgrade to version 5. 5 immediately.
The researchers discovered that it was possible to craft an API call that grants organization administrator privileges to one of their bots.