Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99gj-9798-gpx5

Опубликовано: 25 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.

A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.

EPSS

Процентиль: 62%
0.00425
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-319
CWE-732

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.

EPSS

Процентиль: 62%
0.00425
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-319
CWE-732