PT-2023-21644 · Unknown · Rocket.Chat

Priyank_Parmar

·

Publicado

2023-05-09

·

Atualizado

2023-05-17

·

CVE-2023-28316

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rocket.chat (affected versions not specified)
Description A security issue has been found in the implementation of 2FA on the rocket.chat platform. When 2FA is activated, other active sessions are not invalidated. This could allow an attacker to keep access to a compromised account even after 2FA is enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28316

Produtos afetados

Rocket.Chat