A information disclosure... CVE-2022-35249

- AV AC AU C I A
发布: 2022-09-23
修订: 2024-11-21

A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息