PT-2024-28648 · Rocket.Chat · Rocket.Chat

·

CVE-2024-39713

·

Published

2024-08-05

·

Updated

2025-12-31

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 6.10.1
Description A Server-Side Request Forgery (SSRF) affects Rocket.Chat’s Twilio webhook endpoint. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access internal systems. Approximately 1781 internet-exposed instances have been identified. The issue allows attackers to redirect requests, potentially exposing sensitive data. The vulnerable component is the Twilio webhook endpoint, specifically the handling of requests to this endpoint. The webhook functionality is susceptible to manipulation, allowing an attacker to control the destination of server-side requests.
Recommendations Versions prior to 6.10.1 should be updated to version 6.10.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39713
GHSA-FFXG-5F8M-H72J

Affected Products

Rocket.Chat