6.1
CVSSv3

CVE-2019-19775

Published: 18/12/2019 Updated: 18/12/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 517
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The image thumbnailing handler in Zulip Server versions 1.9.0 to prior to 2.0.8 allowed an open redirect that was visible to logged-in users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zulip zulip server

Github Repositories

Pysa Github Action Python Static Analyzer (Pysa) is a security-focused static analysis tool that tracks flows of data from where they originate to where they terminate in a dangerous location Pysa has been used to detect and disclose security issues on open source Python projects in the past, such as CVE-2019-19775 The Pysa GitHub Action enables you to run Pysa in CI and

GitHub Action for Pysa

Pysa Github Action Python Static Analyzer (Pysa) is a security-focused static analysis tool that tracks flows of data from where they originate to where they terminate in a dangerous location Pysa has been used to detect and disclose security issues on open source Python projects in the past, such as CVE-2019-19775 The Pysa GitHub Action enables you to run Pysa in CI and