CVE-2023-28357: Infoleak
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28357?
CVE-2023-28357 has been classified as a high severity vulnerability due to its potential to expose private channel member information.
How do I fix CVE-2023-28357?
To fix CVE-2023-28357, update your Rocket.Chat instance to a version above 6.0.0 where the vulnerability has been addressed.
What type of vulnerability is CVE-2023-28357?
CVE-2023-28357 is an access control vulnerability that allows unauthorized users to determine channel membership.
Who is affected by CVE-2023-28357?
Authenticated users of Rocket.Chat versions below 6.0.0 are affected by CVE-2023-28357.
What impact does CVE-2023-28357 have on user privacy?
CVE-2023-28357 may lead to privacy breaches by allowing unauthorized users to enumerate members of private channels.