File tree Expand file tree Collapse file tree 1 file changed +13
-0
lines changed
Expand file tree Collapse file tree 1 file changed +13
-0
lines changed Original file line number Diff line number Diff line change @@ -39,6 +39,19 @@ It doesn't include
3939
4040## Unreleased
4141
42+ * Fixed an issue where a crafted, malformed image link in a message
43+ sent by an authenticated user could lead to credential disclosure if
44+ a user taps on the image to expand it. (CVE-2022 -35962)
45+
46+ This issue was discovered internally by the Zulip developers, and the
47+ vulnerability has likely not been exploited in the wild prior to this
48+ disclosure. In particular, an analysis of all messages on Zulip Cloud
49+ found none that could have exploited the issue.
50+
51+ Zulip Cloud has already been updated to make the issue impossible to
52+ exploit there. Zulip server administrators should do the same by
53+ upgrading to Zulip Server 5.6 or later.
54+
4255
4356## 27.189 (2022-07-01)
4457
You can’t perform that action at this time.
0 commit comments