PT-2022-21156 · Unknown · Rocket.Chat

Rolfzur

·

Published

2022-09-23

·

Updated

2022-09-27

·

CVE-2022-32217

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 4.6.4
Description A cleartext storage of sensitive information exists due to an Oauth token being leaked in plaintext in Rocket.Chat logs.
Recommendations For versions prior to 4.6.4, update to version 4.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Rocket.Chat logs to minimize the risk of exploitation.

Exploit

Fix

Insertion into Log File

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-32217

Affected Products

Rocket.Chat