Skip to content

Commit b25c238

Browse files
committed
changelog: Document cherry-picked changes since v27.189
1 parent 4202744 commit b25c238

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

docs/changelog.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,19 @@ It doesn't include
3939

4040
## Unreleased
4141

42+
* Fixed an issue where a crafted, malformed image link in a message
43+
sent by an authenticated user could lead to credential disclosure if
44+
a user taps on the image to expand it. (CVE-2022-35962)
45+
46+
This issue was discovered internally by the Zulip developers, and the
47+
vulnerability has likely not been exploited in the wild prior to this
48+
disclosure. In particular, an analysis of all messages on Zulip Cloud
49+
found none that could have exploited the issue.
50+
51+
Zulip Cloud has already been updated to make the issue impossible to
52+
exploit there. Zulip server administrators should do the same by
53+
upgrading to Zulip Server 5.6 or later.
54+
4255

4356
## 27.189 (2022-07-01)
4457

0 commit comments

Comments
 (0)