CVE-2022-32220
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server meth
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
MEDIUM · CVSS 6.5
EPSS 0.0036
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0