Information Disclosure Vulnerability in Rocket.Chat <v5: getUserMentionsByChannel Method Allows Unauthorized Access to Private Messages

Information Disclosure Vulnerability in Rocket.Chat <v5: getUserMentionsByChannel Method Allows Unauthorized Access to Private Messages

CVE-2022-35249 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

Learn more about our Cis Benchmark Audit For Server Software.