Rocket.Chat Incorrect Authorization Information Disclosure Vulnerability

Vulnerability

An information disclosure vulnerability due to incorrect authorization has been identified in Rocket.Chat. This issue allows remote attackers to access sensitive information from affected installations. The vulnerability resides in the web service, which by default listens on TCP port 3000. Notably, no authentication is required to exploit this flaw.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information within the application.

Remediation

Users can upgrade to Rocket.Chat versions 7.8.0, 7.7.2, 7.6.4, 7.5.3, 7.4.4, or 7.3.6 to address this vulnerability.

Added: Sep 2, 2025, 8:20 PM
Updated: Sep 2, 2025, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.6
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.