PT-2024-28648 · Rocket.Chat · Rocket.Chat
Mokusou
·
Published
2024-08-05
·
Updated
2025-12-31
·
CVE-2024-39713
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rocket.Chat versions prior to 6.10.1
Description
A Server-Side Request Forgery (SSRF) affects Rocket.Chat’s Twilio webhook endpoint. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access internal systems. Approximately 1781 internet-exposed instances have been identified. The issue allows attackers to redirect requests, potentially exposing sensitive data. The vulnerable component is the Twilio webhook endpoint, specifically the handling of requests to this endpoint. The
webhook functionality is susceptible to manipulation, allowing an attacker to control the destination of server-side requests.Recommendations
Versions prior to 6.10.1 should be updated to version 6.10.1 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocket.Chat