CVE-2022-32219
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.
Affected (1)
Products: Rocket.chat: Rocket.chat
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.7.5 |
References (2)
Source: support@hackerone.com
ExploitIssue TrackingMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingMitigationThird Party Advisory
Timeline
No history available yet.