Improper Authentication Vulnerability in Rocket.Chat Products by Rocket.Chat
CVE-2022-35248
8.8HIGH
What is CVE-2022-35248?
An improper authentication vulnerability exists in Rocket.Chat that enables the bypass of two-factor authentication during the login process when configured to use Central Authentication Service (CAS). This flaw affects versions of Rocket.Chat prior to v5, as well as v4.8.2 and v4.7.5, posing a risk to user account security and facilitating unauthorized access.
Affected Version(s)
Rocket.Chat Fixed in versions 4.7.5, 4.8.2, 5.0.0>