PT-2022-4943 · Unknown · Rocket.Chat

·

CVE-2022-32218

·

Published

2022-06-01

·

Updated

2023-07-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 5 Rocket.Chat versions prior to 4.8.2 Rocket.Chat versions prior to 4.7.5
Description An information disclosure issue exists due to insufficient input validation in the actionLinkHandler method, allowing Message ID Enumeration with Regex MongoDB queries. This could enable a remote attacker to disclose protected information.
Recommendations For Rocket.Chat versions prior to 5, update to version 5 or later. For Rocket.Chat versions prior to 4.8.2, update to version 4.8.2 or later. For Rocket.Chat versions prior to 4.7.5, update to version 4.7.5 or later.

Exploit

Fix

RCE

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06135
CVE-2022-32218

Affected Products

Rocket.Chat