PT-2024-28648 · Rocket.Chat · Rocket.Chat

Mokusou

·

Published

2024-08-05

·

Updated

2025-12-31

·

CVE-2024-39713

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 6.10.1
Description A Server-Side Request Forgery (SSRF) affects Rocket.Chat’s Twilio webhook endpoint. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access internal systems. Approximately 1781 internet-exposed instances have been identified. The issue allows attackers to redirect requests, potentially exposing sensitive data. The vulnerable component is the Twilio webhook endpoint, specifically the handling of requests to this endpoint. The webhook functionality is susceptible to manipulation, allowing an attacker to control the destination of server-side requests.
Recommendations Versions prior to 6.10.1 should be updated to version 6.10.1 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-39713
GHSA-FFXG-5F8M-H72J

Affected Products

Rocket.Chat