Логотип exploitDog
bind:CVE-2022-32219
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-32219

Количество 2

Количество 2

nvd логотип

CVE-2022-32219

больше 3 лет назад

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4w54-c3hg-qqrv

больше 3 лет назад

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-32219

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4w54-c3hg-qqrv

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу