Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cjx-7cj6-qvq3

Опубликовано: 25 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

EPSS

Процентиль: 48%
0.00247
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

EPSS

Процентиль: 48%
0.00247
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-862