MEDIUM
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room
Published Sep 23, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.75%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.