Access Control Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2023-28357
What is CVE-2023-28357?
A significant flaw has been discovered in Rocket.Chat related to its Slash Command feature, specifically the /mute command. The access control list (ACL) checks are performed after verifying channel membership, which inadvertently allows authenticated users to ascertain whether specific usernames are members of private channels to which they should not have access. This exposure poses a serious risk regarding the confidentiality of channel member information, enabling potential user enumeration attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rocket.Chat This issue has been fixed in version 6.0> and is backported for the supported versions. Check this document for more info: https://docs.rocket.chat/resources/get-support/enterprise-support#rocket.chat-versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
