CVE-2022-32219

CVE-2022-32219

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

Source: CVE-2022-32219

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다