Логотип exploitDog
bind:CVE-2023-28357
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28357

Количество 2

Количество 2

nvd логотип

CVE-2023-28357

больше 2 лет назад

A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-463w-cvvx-2q2c

больше 2 лет назад

A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-28357

A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-463w-cvvx-2q2c

A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу