CVE-2021-3967
NixOS vulnerability analysis and mitigation

Overview

Improper Access Control vulnerability (CVE-2021-3967) was identified in GitHub repository zulip/zulip prior to version 4.10. The vulnerability was related to the API key regeneration functionality in the Zulip chat platform (Debian Tracker).

Technical details

The vulnerability existed in the API key regeneration mechanism where the endpoint was accessible through a regular session authentication instead of requiring the current API key for verification. The issue was fixed by moving the API key regeneration endpoint from '/json/users/me/apikey/regenerate' to '/api/v1/users/me/apikey/regenerate' and implementing proper authentication checks requiring the current API key (Zulip Github).

Impact

The vulnerability could allow an attacker with access to a user's session to regenerate and obtain new API keys without having access to the current API key, potentially leading to unauthorized access to API functionality (Zulip Github).

Mitigation and workarounds

The issue was fixed in Zulip version 4.10 by implementing proper authentication checks for API key regeneration. The fix involves requiring authentication with the current API key through HTTP Basic auth mechanism when requesting a new API key (Zulip Github).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management