PT-2021-15259 · Unknown · Rocket.Chat

Khekhe

·

Published

2021-05-27

·

Updated

2022-08-30

·

CVE-2021-22892

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 3.13 Rocket.Chat version 3.12.2 Rocket.Chat version 3.11.3
Description An information disclosure issue exists in the Rocket.Chat server that allows email addresses to be disclosed through enumeration and validation checks.
Recommendations For Rocket.Chat versions prior to 3.13, update to version 3.13 or later. For Rocket.Chat version 3.12.2, update to version 3.13 or later. For Rocket.Chat version 3.11.3, update to version 3.13 or later.

Exploit

Fix

Information Disclosure

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2021-22892

Affected Products

Rocket.Chat