Логотип exploitDog
bind:CVE-2022-35246
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-35246

Количество 2

Количество 2

nvd логотип

CVE-2022-35246

больше 3 лет назад

A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9xw6-hr9q-88xg

больше 3 лет назад

A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-35246

A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9xw6-hr9q-88xg

A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу