rocket.chat
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*
- < 7.8.0
- < 7.7.2
- < 7.6.4
- < 7.5.3
- < 7.4.4
- < 7.3.6
An information disclosure vulnerability due to incorrect authorization has been identified in Rocket.Chat. This issue allows remote attackers to access sensitive information from affected installations. The vulnerability resides in the web service, which by default listens on TCP port 3000. Notably, no authentication is required to exploit this flaw.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information within the application.
Users can upgrade to Rocket.Chat versions 7.8.0, 7.7.2, 7.6.4, 7.5.3, 7.4.4, or 7.3.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.