CVE-2022-35249
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
MEDIUM · CVSS 4.3
EPSS 0.00202
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0