First published: Fri Sep 23 2022(Updated: )
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this information disclosure vulnerability is CVE-2022-32220.
The title of this information disclosure vulnerability in Rocket.Chat <v5 is 'An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.'
The severity of CVE-2022-32220 is medium with a severity value of 6.5.
The affected software by this vulnerability is Rocket.Chat <v5.
To fix this vulnerability in Rocket.Chat <v5, an update or patch should be released by the Rocket.Chat team.