First published: Fri Sep 23 2022(Updated: )
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <4.7.5 | |
Rocket.Chat Rocket.Chat | >=4.8.0<4.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35248 is an improper authentication vulnerability in Rocket.Chat versions below v5, v4.8.2, and v4.7.5 that allows bypassing two-factor authentication when using CAS during login.
CVE-2022-35248 has a severity rating of 8.8 (high).
Rocket.Chat versions below v5, v4.8.2, and v4.7.5 are affected by CVE-2022-35248.
Two-factor authentication can be bypassed in Rocket.Chat versions below v5, v4.8.2, and v4.7.5 when using CAS during login.
For more information about CVE-2022-35248, you can refer to the following link: <a href='https://hackerone.com/reports/1448268'>https://hackerone.com/reports/1448268</a>