First published: Thu May 27 2021(Updated: )
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <3.11.3 | |
Rocket.Chat Rocket.Chat | >=3.12.0<3.12.2 | |
Rocket.Chat Rocket.Chat | =3.12.3 | |
Rocket.Chat Rocket.Chat | =3.12.4 | |
Rocket.Chat Rocket.Chat | =3.12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.