First published: Thu May 11 2023(Updated: )
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited impact.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28359 has been classified as a high-severity vulnerability due to its potential impact on server response times.
To remediate CVE-2023-28359, ensure that your Rocket.Chat instance is updated to version 6.0.0 or later.
CVE-2023-28359 affects all versions of Rocket.Chat prior to 6.0.0 that have custom emojis uploaded.
No, CVE-2023-28359 can be exploited by unauthenticated users.
CVE-2023-28359 may cause a delay in server response when the vulnerability is exploited.