First published: Fri Sep 23 2022(Updated: )
A information disclosure vulnerability exists in Rockert.Chat <v5 due to /api/v1/chat.getThreadsList lack of sanitization of user inputs and can therefore leak private thread messages to unauthorized users via Mongo DB injection.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32229 is an information disclosure vulnerability in Rocket.Chat version 5.0 and below.
CVE-2022-32229 allows unauthorized users to access private thread messages by exploiting a lack of input sanitization in the /api/v1/chat.getThreadsList endpoint.
CVE-2022-32229 has a severity value of 4.3, which is considered medium.
To fix CVE-2022-32229, it is recommended to update Rocket.Chat to a version above 5.0 that includes a fix for this vulnerability.
You can find more information about CVE-2022-32229 in the following HackerOne report: <https://hackerone.com/reports/1446767>