Access Control Vulnerability in Rocket.Chat by Rocket.Chat
CVE-2023-28357
4.3MEDIUM
What is CVE-2023-28357?
A significant flaw has been discovered in Rocket.Chat related to its Slash Command feature, specifically the /mute command. The access control list (ACL) checks are performed after verifying channel membership, which inadvertently allows authenticated users to ascertain whether specific usernames are members of private channels to which they should not have access. This exposure poses a serious risk regarding the confidentiality of channel member information, enabling potential user enumeration attacks.
Affected Version(s)
Rocket.Chat This issue has been fixed in version 6.0> and is backported for the supported versions. Check this document for more info: https://docs.rocket.chat/resources/get-support/enterprise-support#rocket.chat-versions