Access Control Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2023-28357

4.3MEDIUM

Key Information:

Vendor
CVE Published:
11 May 2023

What is CVE-2023-28357?

A significant flaw has been discovered in Rocket.Chat related to its Slash Command feature, specifically the /mute command. The access control list (ACL) checks are performed after verifying channel membership, which inadvertently allows authenticated users to ascertain whether specific usernames are members of private channels to which they should not have access. This exposure poses a serious risk regarding the confidentiality of channel member information, enabling potential user enumeration attacks.

Affected Version(s)

Rocket.Chat This issue has been fixed in version 6.0> and is backported for the supported versions. Check this document for more info: https://docs.rocket.chat/resources/get-support/enterprise-support#rocket.chat-versions

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.