Description
A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-38142 | A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions. |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/917946 |
|
History
Thu, 22 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-05-22T18:51:50.487Z
Reserved: 2022-07-06T00:00:00.000Z
Link: CVE-2022-35250
Updated: 2024-08-03T09:29:17.467Z
Status : Modified
Published: 2022-09-23T19:15:14.107
Modified: 2025-05-22T19:15:33.913
Link: CVE-2022-35250
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD