PT-2022-22653 · Unknown · Rocket.Chat

Gronke

·

Published

2022-09-23

·

Updated

2023-06-29

·

CVE-2022-35246

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 5 Rocket.Chat versions prior to 4.8.2 Rocket.Chat versions prior to 4.7.5
Description A NoSQL-Injection information disclosure issue exists in the getS3FileUrl Meteor server method, which can disclose arbitrary file upload URLs to users that should not be able to access.
Recommendations For versions prior to 5, update to version 5 or later. For versions prior to 4.8.2, update to version 4.8.2 or later. For versions prior to 4.7.5, update to version 4.7.5 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-35246

Affected Products

Rocket.Chat